{
 "version": "1.8.0",
 "slug": "501r-community-benefit-compliance-engine",
 "title": "FacilityFile — 501(r) Financial-Assistance & Community-Benefit Compliance Engine",
 "vertical": "Nonprofit hospital tax-exemption compliance / IRC §501(r)",
 "seed": {
  "s": "501r-community-benefit-compliance-engine",
  "t": "FacilityFile — 501(r) Financial-Assistance & Community-Benefit Compliance Engine",
  "v": "Nonprofit hospital tax-exemption compliance / IRC §501(r)",
  "r": "R2",
  "m": "1"
 },
 "product": {
  "slug": "501r-community-benefit-compliance-engine",
  "project_name": "FacilityFile",
  "project_type": "per-facility, per-cycle §501(r) financial-assistance and community-benefit compliance-file production service",
  "vertical": "Nonprofit hospital tax-exemption compliance / IRC §501(r)",
  "audience": "nonprofit hospital and health-system CFOs, VPs Finance, Compliance Officers, and Tax Directors, standalone facilities to 20-facility systems, no in-house tax-exempt counsel",
  "geography": "United States (federally regulated §501(r) hospitals plus ~20-state charity-care overlays), no single-state beachhead required — outreach concentrated in states with dense standalone/rural nonprofit-hospital populations",
  "scale_expectation": "pilot cohort hard-capped at 5 facilities in the first 90 days, then 10, then a mandatory pause to measure; steady-state per-facility annual subscription plus triennial CHNA cycles across roughly 2,900 nonprofit community hospitals, no hard external deadline beyond each facility's own CHNA clock and annual AGB recalculation",
  "core_workflows": [
   "Policy/remittance/CHNA data intake & completeness check",
   "Requirement Diff against the 26 CFR 1.501(r) checklist & AGB Workpaper computation",
   "Corrected FAP/EMCP, CHNA Package, and Schedule H Narrative drafting",
   "Compliance Analyst completeness check & TEO Attorney + Healthcare CPA sign-off coordination"
  ],
  "discovery": {
   "one_line_purpose": "On FacilityFile, a nonprofit hospital facility stops guessing whether it satisfies §501(r) and starts getting a filed-ready, dual-signed Compliance File every cycle. Policies, prior CHNA, and remittance data are extracted and reconciled at intake, the Requirement Diff is run against the federal checklist, a Compliance Analyst checks completeness, a TEO Attorney signs the compliance determination, and a Healthcare CPA signs the AGB Workpaper and Schedule H representation.",
   "primary_users": [
    "Hospital CFO or Compliance Officer (standalone facilities under roughly $400M net patient revenue)",
    "System Tax Director or Chief Compliance Officer (5-20 facility systems on staggered CHNA clocks)",
    "TEO Attorney and Healthcare CPA (independently engaged to sign the compliance determination and the AGB/Schedule H representation)"
   ],
   "jobs_to_be_done": [
    "Get a complete, current, examiner-ready Compliance File without hiring tax-exempt counsel onto staff",
    "Answer a board or auditor's exposure question with a TEO Attorney's signed determination, not a guess",
    "Track and meet a completely different CHNA clock, AGB recalculation date, and state overlay in every facility a multi-facility system operates"
   ],
   "value_prop": "FacilityFile turns a facility's scattered policies, remittance data, and prior CHNA into a filed-ready, dual-signed §501(r) Compliance File — defensible to an IRS examiner, a board, or an auditor, with the facility always the party of record on the filing.",
   "competitors": [
    "CHNA consultancies (Crescendo, PRC, RMS) that run the triennial assessment alone, without disclosure/AGB/billing production",
    "Healthcare CPA and health-law advisory firms (Baker Tilly, CLA, Forvis Mazars, Nixon Peabody, Krieg DeVault) that sell point-in-time '501(r) reviews,' not a maintained file",
    "Community-benefit reporting software and general healthcare GRC platforms (symplr, Inovaare) that give the hospital a tool to operate, not a signed file",
    "The status quo: rebuilding the FAP/CHNA from a stale prior-year template with no current AGB recalculation"
   ],
   "differentiation": "Done-for-you Compliance File production, not a tool to operate: AI-native, always-current tracking of all six §501(r) requirements plus roughly 20 state charity-care overlays, combined with the full production workflow and a coordinated dual sign-off (TEO Attorney + Healthcare CPA) in one done-for-you service, at per-facility pricing sized for the underserved standalone/rural nonprofit hospital the existing fragmented vendors are not structured to serve efficiently.",
   "positioning_statement": "For nonprofit hospital facilities that have never had to produce a §501(r) Compliance File without hiring outside counsel and an actuary-equivalent function, FacilityFile is the done-for-you 501(r) compliance desk that turns raw policies, remittance data, and CHNA inputs into one filed-ready, dual-signed file — unlike a CHNA-only consultancy that handles a single requirement, or a stale template the facility must interpret and file alone."
  },
  "assumptions": [
   {
    "id": "501r-community-benefit-compliance-engine-a1",
    "statement": "Hospital CFOs and Compliance Officers will pay for a done-for-you Compliance File over continuing to book prior-year template renewals unverified, once shown a concrete Facility Readiness Scan finding.",
    "confidence": "medium",
    "impact_if_wrong": "severe",
    "revisit_trigger": "First 10 pilot findings-consult sales conversations — reject the wedge if willingness-to-pay signal is absent."
   },
   {
    "id": "501r-community-benefit-compliance-engine-a2",
    "statement": "A Facility Compliance Audit & Correction File can hit the 3-4-week launch delivery target from facility-supplied policies, prior CHNA, and 12 months of remittance data alone, without a facility-side system integration.",
    "confidence": "medium",
    "impact_if_wrong": "high",
    "revisit_trigger": "First 3-5 pilot audits."
   },
   {
    "id": "501r-community-benefit-compliance-engine-a3",
    "statement": "Facilities tolerate AI-assisted policy extraction and Requirement Diff drafting when the TEO Attorney's and Healthcare CPA's signatures are explicit on every Compliance File.",
    "confidence": "medium",
    "impact_if_wrong": "high",
    "revisit_trigger": "First board or auditor question about a delivered file's provenance."
   },
   {
    "id": "501r-community-benefit-compliance-engine-a4",
    "statement": "Readiness Scan-to-audit conversion reaches at least 15-25% among qualified, triggered facilities (IRS exam letter, upcoming CHNA deadline, or stale FAP).",
    "confidence": "low",
    "impact_if_wrong": "severe",
    "revisit_trigger": "Day-90 pilot-cohort conversion measurement (explicit kill/pivot gate at 15%)."
   },
   {
    "id": "501r-community-benefit-compliance-engine-a5",
    "statement": "Logical, per-facility data isolation (not single-tenant infrastructure per facility) is acceptable to the pilot cohort.",
    "confidence": "medium",
    "impact_if_wrong": "high",
    "revisit_trigger": "Any prospect (e.g. a multi-facility system) with a hard single-tenant compliance clause."
   }
  ],
  "unknowns": [
   {
    "id": "501r-community-benefit-compliance-engine-u1",
    "question": "Which specific TEO Attorney and Healthcare CPA sign off on the first cohort's Compliance Files?",
    "blocks": "Any commercial engagement; the dual-signature invariant.",
    "resolution_path": "Named TEO Attorney and Healthcare CPA + engagement agreements on file before the first paid audit."
   },
   {
    "id": "501r-community-benefit-compliance-engine-u2",
    "question": "What is the true Readiness Scan-to-audit conversion rate among triggered, qualified facilities?",
    "blocks": "Pricing hypothesis; scaling decision.",
    "resolution_path": "5-facility pilot cohort with explicit pricing conversation, measured against the Day-90 checkpoint (15% kill gate, 25% target)."
   },
   {
    "id": "501r-community-benefit-compliance-engine-u3",
    "question": "How much does per-state overlay coverage actually reduce Compliance Analyst review minutes by Day 90?",
    "blocks": "Unit-economics model; throughput assumptions.",
    "resolution_path": "Instrument Compliance Analyst minutes per file from pilot 1; compare to the 240-minute-launch to 150-minute-Day-90 licensed-minute target."
   }
  ],
  "expert_panel": [
   {
    "role": "Product Strategy",
    "key_concern": "Is the Facility Compliance Audit narrow enough to sell in weeks without a custom integration?",
    "recommendation": "Launch scoped to a single facility's current-cycle FAP/EMCP/AGB against a 12-month remittance lookback; expand to System Portfolio only after the pilot converts.",
    "dissent": "May understate the recurring-revenue story to early prospects expecting an always-on dashboard."
   },
   {
    "role": "Software Architecture",
    "key_concern": "Are we defaulting to a facility-facing portal the pilot doesn't need yet?",
    "recommendation": "Single deployable modular monolith; upload-link/email intake only at launch, no facility portal.",
    "dissent": "May read as under-built to a system referral partner expecting a branded dashboard."
   },
   {
    "role": "Frontend / UX",
    "key_concern": "Is the evidence chain (remittance line to AGB Workpaper to TEO Attorney/Healthcare CPA decision) visible in every review-facing view?",
    "recommendation": "Every Compliance File section renders its CFR citation, matched policy clause, and reviewer decision in one glance.",
    "dissent": "Adds density a non-specialist reviewer might call cluttered."
   },
   {
    "role": "Backend / Data",
    "key_concern": "Is the evidence trail append-only and reconstructable for an IRS examination or board diligence request years later?",
    "recommendation": "Event-sourced evidence log for every compliance-cycle state transition; hash-chained artifact snapshots.",
    "dissent": "More write-path complexity than plain CRUD; requires schema discipline as overlay formats evolve."
   },
   {
    "role": "AI / ML",
    "key_concern": "Are Requirement Diff findings grounded in the 26 CFR 1.501(r) text and never a free-form guess?",
    "recommendation": "Retrieval-first classification citing the specific CFR subsection; deterministic AGB math in code, never the model; mandatory Compliance Analyst gate before any facility- or examiner-facing claim.",
    "dissent": "Slower per-cycle than a fully automated tool; may frustrate a prospect expecting instant results."
   },
   {
    "role": "Security",
    "key_concern": "Is one facility's remittance and policy data isolated from every other facility's?",
    "recommendation": "Row-level auth, per-tenant retrieval indices, log-scrubbing of remittance figures and any incidental PHI.",
    "dissent": "None recorded this run."
   }
  ],
  "strategy": {
   "business_model": "Per-facility, per-cycle flat fee (Facility Compliance Audit & Correction File one-time, Annual Compliance File subscription, Triennial CHNA Package, Remediation & Defense per matter); never hourly, never a percentage of hospital net patient revenue or reserves — rejected outright given the exemption-protection purpose of the work",
   "revenue_streams": [
    "Facility Compliance Audit & Correction File (one-time wedge)",
    "Annual Compliance File subscription (recurring)",
    "Triennial CHNA + Implementation Strategy Package (recurring, 3-year cycle)",
    "Remediation & Defense (event-driven, exam/deadline season)",
    "System Portfolio bundle (5+ facilities, volume discount)"
   ],
   "moat": [
    "26 CFR 1.501(r) requirement corpus and state charity-care overlay library, compounding with every facility",
    "Persistent, tracked CHNA-clock and AGB-recalculation calendar data across the pilot cohort",
    "Named TEO Attorney's and Healthcare CPA's signed accountability on every file",
    "Gold-standard file library and examiner red-team question set that hardens with every engagement"
   ],
   "gtm": [
    "Founder-led educational content + anonymized Facility Readiness Scan teardowns",
    "State hospital association and rural-health-network webinars and member-benefit pilots",
    "Healthcare CPA / health-law firm referral partnerships (white-label the file behind their opinion)"
   ],
   "pricing_hypothesis": "Facility Readiness Scan free (unlimited); Facility Compliance Audit & Correction File $14,000-$28,000 one-time; Annual Compliance File subscription $12,000-$24,000/yr — priced under a full law-firm-plus-CPA-consultant bundle and sized for the standalone hospital, validated against 10+ pricing conversations before scaling spend.",
   "kill_criteria": [
    "No signed pilot facility in 4 weeks of qualified outreach",
    "Compliance Analyst median cycle time exceeds the 4-week launch target after pilot facility 5",
    "No paid annual-subscription conversion by Day 90",
    "A released Compliance File causes a documented, FacilityFile-caused examiner finding or facility-relationship incident"
   ]
  },
  "security": {
   "stride": [
    {
     "threat": "Spoofing",
     "scenario": "Attacker impersonates the TEO Attorney or Healthcare CPA to approve a fabricated Requirement Diff finding or sign a Compliance File.",
     "mitigation": "SSO with MFA; signer identity bound to a cryptographic session claim, not a form field."
    },
    {
     "threat": "Tampering",
     "scenario": "Historical remittance data or policy artifacts edited after the fact to hide a bad AGB tie-out.",
     "mitigation": "Append-only evidence log; hash-chained artifact snapshots; diff view on every reviewer surface."
    },
    {
     "threat": "Repudiation",
     "scenario": "A reviewer denies approving a Requirement Diff finding or signing a Compliance File that later proves wrong.",
     "mitigation": "Signed attestations with server-side timestamp + reviewer identity; export bundle includes signature manifest."
    },
    {
     "threat": "Information Disclosure",
     "scenario": "Cross-facility leak of one hospital's remittance or policy data through shared indices, logs, or prompts.",
     "mitigation": "Tenant-scoped row-level auth; PHI/financial-data scrubbing in logs; retrieval indices partitioned per facility; remittance data de-identified to minimum-necessary before ingestion."
    },
    {
     "threat": "Denial of Service",
     "scenario": "A runaway extraction job or bulk remittance import exhausts shared workers during a CHNA-deadline crunch.",
     "mitigation": "Per-tenant concurrency + budget caps; circuit breaker on model calls; degrade-gracefully queue."
    },
    {
     "threat": "Elevation of Privilege",
     "scenario": "A Compliance Analyst acquires TEO Attorney or Healthcare CPA sign-off capability via a workflow shortcut.",
     "mitigation": "Roles stored in a separate table; capability checks server-side; no client-only role checks."
    }
   ],
   "privacy_posture": "Data-minimization by default; per-facility isolation; BAA/DPA on file before remittance data is accepted; deletion-schedule runbook published.",
   "compliance_targets": [
    "HIPAA Business Associate Agreement program for de-identified remittance data",
    "SOC 2 Type I (year 2 roadmap)",
    "State-by-state UPL/unauthorized-tax-practice boundary review before scaling",
    "IRM 4.70.1 examiner-checklist currency log for every filing cycle"
   ],
   "data_classifications": [
    "Facility policy suite (FAP/EMCP/billing) and CHNA reports (sensitive business data)",
    "Allowed-claims remittance extracts (sensitive, minimum-necessary de-identified financial data)",
    "Facility roster / EIN / state-of-operation data (sensitive, third-party-sourced)",
    "Contact/PII of Facility staff (standard)"
   ]
  },
  "devops": {
   "ci_cd": "PR -> typecheck + unit + snapshot tests -> preview deploy -> main auto-deploys to a single production region; migrations gated on review.",
   "environments": [
    "local",
    "preview (per-PR)",
    "staging (shared)",
    "production (single region + multi-AZ)"
   ],
   "observability": [
    "Structured logs with tenant + request IDs",
    "RED metrics per workflow",
    "Error tracking with source maps",
    "Model-call spans with cost + latency",
    "Weekly SLO review, with a CHNA-deadline-crunch capacity review"
   ],
   "testing_pyramid": [
    "Unit tests on AGB-computation and tie-out validation modules",
    "Component tests on Compliance Analyst exception-queue surfaces",
    "Contract tests on state-overlay parsers",
    "End-to-end smoke test on the intake -> Requirement Diff -> dual sign-off -> delivery path"
   ],
   "accessibility_tests": [
    "axe-core in CI on reviewer-facing surfaces",
    "Keyboard-only walkthrough per workflow",
    "Prefers-reduced-motion honored"
   ],
   "performance_budget": "p95 workflow latency published per module; remittance-extraction cold-path under 30s or shown as a background job."
  },
  "accessibility_i18n_ethics": {
   "wcag_target": "AA",
   "locales": [
    "en-US"
   ],
   "rtl_support": false,
   "ethical_risks": [
    "A Requirement Diff finding or AGB figure released without Compliance Analyst approval",
    "Compliance-determination language read as a legal opinion rather than a licensed attorney's own work product",
    "An error in an AGB Workpaper attributed to AI rather than owned by the reviewing Healthcare CPA"
   ],
   "ethical_guardrails": [
    "Human Compliance Analyst approval required before any Requirement Diff finding or drafted artifact ships to a licensed signer",
    "Deterministic output filter blocks any compliance-determination language in AI-drafted material",
    "AI-usage disclosure available in the engagement letter where relevant"
   ]
  },
  "governance": {
   "ownership": [
    {
     "area": "Product + roadmap",
     "owner": "Executive Sponsor"
    },
    {
     "area": "Architecture + platform",
     "owner": "Engineering Lead"
    },
    {
     "area": "Compliance production + reviewer workflow",
     "owner": "Founder/Compliance Lead"
    },
    {
     "area": "Legal + financial sign-off",
     "owner": "TEO Attorney / Healthcare CPA"
    },
    {
     "area": "Design system",
     "owner": "Design Lead"
    },
    {
     "area": "SEO + content",
     "owner": "Content Lead"
    }
   ],
   "docs_required": [
    "ADR log (checked in)",
    "Owner-action ledger",
    "Evidence register",
    "STRIDE threat model",
    "Runbook: incident, restore, breach notification",
    "Compliance Analyst playbook + signature log"
   ],
   "naming_conventions": [
    "kebab-case slugs for blueprints and routes",
    "camelCase for TypeScript identifiers",
    "SCREAMING_SNAKE_CASE for environment variables",
    "Verb-first action names (e.g., generate-compliance-file)"
   ],
   "change_control": "ADR-per-major-decision; migrations require review; production deploys gated on green CI + owner-action ledger check."
  },
  "risk_register": [
   {
    "id": "501r-community-benefit-compliance-engine-r1",
    "risk": "An examiner-facing Compliance File claim proves incorrect",
    "likelihood": "medium",
    "impact": "severe",
    "mitigation": "Every Requirement Diff finding linked to a cited CFR subsection + TEO Attorney/Healthcare CPA sign-off",
    "contingency": "Retraction workflow; facility-notification template; evidence-log export within 24 hours",
    "owner": "legal"
   },
   {
    "id": "501r-community-benefit-compliance-engine-r2",
    "risk": "AI hallucination in a delivered Requirement Diff finding or drafted policy clause",
    "likelihood": "medium",
    "impact": "high",
    "mitigation": "Retrieval-first pipeline + structured output validation + Compliance Analyst gate",
    "contingency": "Reviewer-triggered rollback + regeneration; incident postmortem published to the facility",
    "owner": "engineering"
   },
   {
    "id": "501r-community-benefit-compliance-engine-r3",
    "risk": "Cross-facility financial/policy data leak",
    "likelihood": "low",
    "impact": "severe",
    "mitigation": "Row-level auth + per-tenant retrieval indices + log-scrubbing",
    "contingency": "Breach-notification runbook; forced credential rotation; scoped tenant kill switch",
    "owner": "engineering"
   },
   {
    "id": "501r-community-benefit-compliance-engine-r4",
    "risk": "Pilot facility churns before converting to an annual subscription",
    "likelihood": "medium",
    "impact": "high",
    "mitigation": "Weekly working-session cadence during pilot; documented value moments; owner-action ledger",
    "contingency": "Structured exit interview; write learnings into ICP + pricing hypothesis",
    "owner": "owner"
   },
   {
    "id": "501r-community-benefit-compliance-engine-r5",
    "risk": "A healthcare GRC vendor ships free, good-enough tracking with a filing workflow",
    "likelihood": "medium",
    "impact": "high",
    "mitigation": "Positioning as the signed, done-for-you file, not a tool the facility must operate; TEO Attorney/Healthcare CPA sign-off as the human moat software won't replicate",
    "contingency": "Reposition as \"we operate whatever GRC tool exists\"; lean harder into Remediation & Defense",
    "owner": "owner"
   }
  ],
  "roadmap": [
   {
    "phase": "Phase 0 — Discovery + pilot LOI",
    "weeks": "Weeks 1-2",
    "outcomes": [
     "3-5 pilot facility LOIs",
     "Evidence pack from each pilot facility",
     "Written ICP + pricing hypothesis"
    ],
    "exit_criteria": [
     "≥3 LOIs signed",
     "Owner-action ledger populated per facility",
     "TEO Attorney and Healthcare CPA identity confirmed"
    ],
    "kill_criteria": [
     "<2 LOIs after 2 weeks",
     "No willingness-to-pay signal above pilot price"
    ]
   },
   {
    "phase": "Phase 1 — Thin vertical slice",
    "weeks": "Weeks 3-4",
    "outcomes": [
     "Intake -> Requirement Diff -> dual sign-off -> delivery working end-to-end for one state overlay",
     "Evidence trail wired",
     "Instrumentation live"
    ],
    "exit_criteria": [
     "1 real Facility Compliance Audit delivered + dual-signed",
     "p95 workflow latency published"
    ],
    "kill_criteria": [
     "Dual sign-off cycle >4 weeks",
     "Evidence bundle cannot be reconstructed on demand"
    ]
   },
   {
    "phase": "Phase 2 — Pilot cohort",
    "weeks": "Weeks 3-11",
    "outcomes": [
     "5 pilot facilities scanned and audited",
     "First standard-price annual-subscription conversion",
     "SOC 2 Type I scoping"
    ],
    "exit_criteria": [
     "≥1 standard-price contract",
     "Post-audit debrief trust signal captured",
     "Postmortem cadence in place"
    ],
    "kill_criteria": [
     "No standard-price conversion by Day 90",
     "Readiness Scan-to-audit conversion below 15%"
    ]
   },
   {
    "phase": "Phase 3 — Recurring-desk scale-up",
    "weeks": "Weeks 9-13 (Day 90 checkpoint)",
    "outcomes": [
     "Public commercial launch of the microsite as 'ready'",
     "System Portfolio and Remediation & Defense lines active",
     "Owner-action ledger closed for launch"
    ],
    "exit_criteria": [
     "COGS/rework/cycle-time measured against target",
     "Expansion beyond the pilot cohort gated on targets, not calendar time"
    ],
    "kill_criteria": [
     "Rework rate persistently above 12%",
     "Licensed minutes per file not falling with volume"
    ]
   }
  ],
  "metrics": {
   "north_star": "Signed Compliance Files delivered per month, per facility, with zero material examiner findings",
   "leading": [
    "Pilot facility LOIs signed",
    "Readiness-Scan-to-delivered-audit cycle time",
    "TEO Attorney + Healthcare CPA sign-off cycle time",
    "CFR citation coverage per Requirement Diff finding",
    "Owner-action ledger closure rate"
   ],
   "lagging": [
    "Paid annual-subscription contracts signed",
    "Readiness Scan-to-audit conversion (target ≥25%, pilot gate 15%)",
    "Facility-caught material error rate (target <0.5%)",
    "Facility retention (target ≥85% annualized)"
   ],
   "guardrails": [
    "Model spend per tenant per week",
    "PHI/financial data in logs (target: 0)",
    "Cross-tenant access attempts (target: 0)",
    "p95 workflow latency ceiling"
   ]
  },
  "executive_review": {
   "consensus": "Ship a thin, evidence-linked, dual-signed vertical slice for FacilityFile, wedged on the Facility Readiness Scan. Prefer a boring, single-region modular monolith. Do not launch commercially until owner-action facts close and at least one dual-signed Compliance File has shipped.",
   "dissent": "Executive Sponsor and Privacy/Compliance disagree on launch tempo — Privacy recommends waiting for the full state-by-state UPL/unauthorized-tax-practice review before enabling Remediation & Defense anywhere.",
   "go_no_go": "conditional-go",
   "top_3_risks": [
    "An examiner-facing Compliance File claim proves incorrect",
    "AI hallucination in a delivered Requirement Diff finding or drafted policy clause",
    "Cross-facility financial/policy data leak"
   ],
   "first_10_steps": [
    "Confirm the named TEO Attorney and Healthcare CPA + engagement agreements on file",
    "Populate owner-action ledger with entity, jurisdiction, contact inbox, privacy inbox",
    "Open pilot-cohort intake (cap 5) with explicit pricing conversation",
    "Write ICP + kill/pivot criteria in the plan file",
    "Stand up the evidence-linked intake -> Requirement Diff -> dual sign-off loop",
    "Wire append-only evidence log + hash-chained snapshots",
    "Add row-level auth + tenant-scoped retrieval indices",
    "Instrument scan-request, file-delivery, and sign-off events",
    "Publish the microsite with plain FAQ text only (no FAQ rich-result schema) and noindex until owner-facts close",
    "Schedule the Day-90 kill/pivot review with executive sponsor"
   ]
  }
 },
 "project_site": {
  "slug": "501r-community-benefit-compliance-engine",
  "app_name": "FacilityFile 501(r) compliance desk",
  "archetype": "compliance determination desk",
  "archetype_label": "IRC 501(r) hospital community-benefit compliance desk",
  "reader_role": "CFO / Compliance Officer / Tax Director",
  "one_sentence_app": "FacilityFile is a §501(r) compliance desk for nonprofit hospital facilities that need a dated, cited, examiner-ready Compliance File on every filing cycle before a missed requirement quietly costs the facility its tax exemption.",
  "homepage_sequence": [
   "scene",
   "workflow",
   "instrument",
   "offer",
   "proof",
   "qualification",
   "objections"
  ],
  "hero": {
   "frame_label": "Nonprofit hospital tax-exemption compliance · §501(r) compliance desk",
   "eyebrow": "Hospital CFO or Compliance Officer / an IRS exam letter or CHNA deadline just landed and you're not sure every requirement is covered",
   "interface_title": "FacilityFile 501(r) compliance desk",
   "primary_panel_title": "Facility Compliance Audit #FF-2026-000118 · CHNA + FAP correction · Week 0 of 3-4 week launch SLA",
   "primary_panel_body": "Open Requirement Diff: classify this facility's current policies against the six §501(r) requirements, run the AGB Workpaper computation, and stage the Compliance File for Compliance Analyst release.",
   "side_panel_title": "Before this ships",
   "side_panel_items": [
    "Facility's current FAP/EMCP, prior CHNA, and 12 months of remittance data confirmed complete",
    "AGB Workpaper computed and tie-out checked",
    "TEO Attorney and Healthcare CPA have signed off on the determination and the numbers"
   ],
   "status_metric": "REVIEW",
   "status_label": "dual sign-off gate active"
  },
  "language": {
   "problem_heading": "The facility's moment",
   "mechanism_heading": "Inside the FacilityFile compliance desk",
   "proof_heading": "Why this survives an IRS examination or a board audit",
   "offer_heading": "What leaves the room",
   "objection_heading": "The hard questions",
   "qualification_heading": "Who should not use this",
   "cta_close": "Get your free Facility Readiness Scan — reviewed by a real Compliance Analyst, cited to the current 26 CFR 1.501(r) checklist."
  },
  "modules": [
   {
    "name": "Facility Readiness Scan",
    "job": "Turns one facility's public Form 990/Schedule H and posted FAP/CHNA into a cited gap read within 3 business days, at no cost.",
    "artifact": "free diagnostic gap report"
   },
   {
    "name": "Compliance File",
    "job": "The dated, cited, examiner-ready deliverable — corrected FAP/EMCP, AGB Workpaper, and Schedule H Narrative — with a TEO Attorney determination and a Healthcare CPA sign-off.",
    "artifact": "delivered compliance file"
   },
   {
    "name": "System Portfolio Review",
    "job": "A full-portfolio sweep for System Portfolio subscribers catching drift a staggered CHNA clock or a state-overlay change introduces.",
    "artifact": "portfolio review report"
   }
  ],
  "checkpoints": [
   {
    "label": "Deterministic Rule Check",
    "pass": "requirement threshold clear, request proceeds to AI classification",
    "fail": "forces a flagged finding with a mandatory Correction Pathway attempt"
   },
   {
    "label": "confidence threshold",
    "pass": "at or above the analyst-review confidence band",
    "fail": "routed to the Exception Queue for TEO Attorney or Healthcare CPA escalation regardless of dollar value"
   },
   {
    "label": "Compliance File release",
    "pass": "Compliance Analyst signs off; TEO Attorney and Healthcare CPA co-sign",
    "fail": "stays in review"
   }
  ],
  "signature_scene": "You're the CFO of a 60-bed rural nonprofit hospital with a finance team of two. An IRS exam letter just arrived referencing your facility's §501(r) compliance, and you're not certain your Financial Assistance Policy, your AGB percentage, or your last Community Health Needs Assessment would survive the review. You have no in-house tax-exempt counsel, no actuary-equivalent function, and a board asking whether the exemption is actually safe. This page is built like the compliance desk that exam letter needed before you had to guess."
 },
 "ddd": {
  "slug": "501r-community-benefit-compliance-engine",
  "project_name": "FacilityFile",
  "business_understanding": {
   "summary": "FacilityFile — a nonprofit hospital facility sends its current FAP/EMCP, prior CHNA, and remittance data, and FacilityFile runs the Requirement Diff against the 26 CFR 1.501(r) checklist, computes the AGB Workpaper, drafts a corrected policy suite and Schedule H Narrative, routes the compliance determination to an independently engaged TEO Attorney and the AGB/Schedule H representation to an independently engaged Healthcare CPA, and delivers a dated, examiner-ready Compliance File.",
   "customer_profile": "Nonprofit hospital facilities: standalone/rural community hospitals ($30M-$400M net patient revenue) with no in-house tax-exempt counsel; mid-size health systems (5-20 facilities) on staggered CHNA clocks; newly acquired or converted facilities inheriting non-compliant policies — none with an in-house §501(r) compliance specialist reviewing every requirement.",
   "customer_pain": "A missed CHNA or unadopted implementation strategy triggers a $50,000 excise tax per facility, per year under IRC §4959; an AGB percentage that isn't recalculated at least annually breaks the FAP's own charge-limitation promise; a facility that hasn't made reasonable efforts to determine FAP-eligibility before extraordinary collection action risks a billing/collection finding; and a pattern of failures risks the facility's own income being taxed and the organization's §501(c)(3) exemption being revoked outright. CHNA consultancies and healthcare CPA/law advisory firms describe these gaps as common, good-faith compliance drift, not rare edge cases — a routine operational hazard most standalone hospitals have no systematic check against.",
   "paid_outcome": "A dated, cited, examiner-ready Compliance File for a facility's current filing cycle, protecting the facility's federal tax exemption and the organization's board — reconstructable on demand, defensible to an IRS examiner.",
   "value_creation": "AI compresses policy extraction, Requirement Diff classification, and first-pass drafting; deterministic code owns every requirement pass/fail gate and every AGB dollar calculation; humans own Compliance Analyst sign-off, TEO Attorney legal-determination judgment, Healthcare CPA financial-representation judgment, and anything that touches a novel correction-and-disclosure question; the platform binds them with an append-only evidence log and per-facility isolation.",
   "why_ai_native": "The classify-draft-review-sign loop is only economical with a bounded AI layer feeding deterministic rules. A pure-manual analyst hire cannot hit per-facility pricing at the volumes a growing health-system portfolio generates; a pure-automated tool cannot hold the Compliance Analyst approval gate, absorb a genuinely novel correction-and-disclosure fact pattern, or provide the dual licensed sign-off that gives a facility real exemption protection.",
   "operational_risks": [
    "Compliance Analyst bottleneck during a synchronized CHNA-deadline volume spike",
    "Prompt injection via uploaded policy documents or remittance extracts",
    "Cross-facility retrieval leak, including remittance financial data",
    "Incomplete facts unobtainable at scale (a facility stuck in evidence-gap status past the launch SLA)",
    "A finding read as a legal compliance determination rather than AI-assisted research delivered to the licensed signer of record"
   ],
   "assumptions": [
    "Hospital CFOs will pay a per-facility flat fee for evidence-linked, dual-signed compliance production over continuing to rebuild from a stale template",
    "The workflow can be completed from facility-supplied policies, prior CHNA, and remittance data within the 3-4-week launch / 5-8-business-day Year-1 targets",
    "The vertical tolerates AI-assisted drafts when Compliance Analyst approval is explicit and every delivery is authorized under a signed engagement letter",
    "Logical, per-facility claim isolation (not dedicated infrastructure per facility) is acceptable for the first cohort",
    "Demand persists as a continuous, per-cycle need (annual AGB, triennial CHNA), not a one-time filing event"
   ],
   "validation_questions": [
    "Which states are in scope for the founding cohort's overlay coverage?",
    "What is the actual Readiness-Scan-to-paid conversion rate at pilot pricing vs. standard pricing?",
    "Which existing systems (facility case-management tools, remittance exports, email) must this integrate with day one?",
    "Is there a data-residency constraint for any pilot facility's remittance data?",
    "When does a given state's charity-care overlay stabilize enough to codify a requirement-corpus entry with confidence?"
   ]
  },
  "domain_discovery": {
   "actors": [
    {
     "actor": "CFO / Compliance Officer (economic buyer)",
     "role": "Owns the Facility's compliance engagement; supplies policies and remittance data and authorizes the Requirement Diff process",
     "goals": [
      "Prove every facility is §501(r)-compliant with a signed file examiners can rely on",
      "Avoid becoming an amateur tax-exempt-law expert for every requirement",
      "Have a defensible, examiner-ready file if the facility is questioned"
     ],
     "decisions": [
      "Whether to engage FacilityFile",
      "Which policies/documents to supply per engagement",
      "Whether to sign the engagement letter"
     ],
     "pain_points": [
      "No time to research 26 CFR 1.501(r) and state overlays for every requirement",
      "Doesn't know which facilities are genuinely exposed vs. routine"
     ]
    },
    {
     "actor": "Compliance Analyst",
     "role": "Reviews AI-drafted Requirement Diff findings and artifacts; signs off before any delivery to a licensed signer; triages the Exception Queue",
     "goals": [
      "Release only evidence-backed, correctly cited findings",
      "Protect the facility's exemption and the organization's liability position",
      "Escalate genuinely ambiguous cases, not just dollar-threshold cases"
     ],
     "decisions": [
      "Approve, edit, or escalate a drafted finding",
      "Decide whether an ambiguous overlay question needs TEO Attorney review"
     ],
     "pain_points": [
      "Volume spikes during CHNA-deadline cycles",
      "Genuinely novel fact patterns requiring judgment beyond the requirement corpus"
     ]
    },
    {
     "actor": "TEO Attorney (independently engaged)",
     "role": "Reviews and signs the §501(r) compliance determination and any correction-and-disclosure strategy",
     "goals": [
      "Resolve the compliance determination correctly and defensibly"
     ],
     "decisions": [
      "Sign, request more facts, or decline to certify a determination"
     ],
     "pain_points": [
      "Receiving an escalation without a complete fact and citation history"
     ]
    },
    {
     "actor": "Healthcare CPA (independently engaged)",
     "role": "Reviews and signs the AGB Workpaper and the Schedule H representation",
     "goals": [
      "Certify a tied-out, defensible AGB calculation and Schedule H narrative"
     ],
     "decisions": [
      "Sign, request corrected remittance data, or flag an AGB discrepancy"
     ],
     "pain_points": [
      "Receiving remittance data that doesn't tie out to the FAP's stated method"
     ]
    },
    {
     "actor": "IRS (external)",
     "role": "The regulator whose rules govern every determination; may open an examination",
     "goals": [
      "Confirm hospital facilities are meeting their §501(r) obligations"
     ],
     "decisions": [
      "Clear, question, or examine a facility based on its filed Schedule H and posted policies"
     ],
     "pain_points": [
      "High volume of hospital facilities across many systems and states to review on a triennial cycle"
     ]
    }
   ],
   "glossary": [
    {
     "term": "Facility Readiness Scan",
     "definition": "The free, 3-business-day diagnostic: a facility's public Form 990/Schedule H and posted FAP/CHNA in, a cited gap read out.",
     "used_by": "CFO / Compliance Officer",
     "context": "Facility Intake",
     "example": "Facility Readiness Scan on a standalone rural hospital's posted FAP",
     "notes": "Never called 'assessment', 'audit', or 'review'."
    },
    {
     "term": "Compliance File",
     "definition": "The tracked deliverable: one signed, examiner-ready §501(r) file per facility per filing cycle.",
     "used_by": "All roles",
     "context": "Requirement Compliance",
     "example": "Annual Compliance File for a 12-facility system's largest campus",
     "notes": "Never called 'report' or 'packet'."
    },
    {
     "term": "Requirement Diff",
     "definition": "The AI step comparing a facility's current artifacts to the 26 CFR 1.501(r) checklist, requirement by requirement.",
     "used_by": "AI / Compliance Analyst",
     "context": "Requirement Compliance",
     "example": "Requirement Diff flags a stale FAP translation threshold",
     "notes": "Cites the specific CFR subsection on every finding."
    },
    {
     "term": "AGB Workpaper",
     "definition": "The Amounts Generally Billed percentage computation and its supporting workpaper, recalculated at least annually from allowed-claims data.",
     "used_by": "AI / Healthcare CPA",
     "context": "Actuarial-Style Computation",
     "example": "AGB Workpaper computed from 12 months of 835 remittance data",
     "notes": "Signed only by the Healthcare CPA."
    }
   ],
   "decisions": [
    {
     "decision": "Does this Facility artifact pass its applicable Deterministic Rule Checks?",
     "who": "Deterministic code, no human judgment",
     "inputs": [
      "Current FAP/EMCP text",
      "Prior CHNA date",
      "AGB remittance data"
     ],
     "rule": "CHNA-clock, AGB-recalculation-trigger, and LEP-language-threshold checks run in code against the requirement corpus current thresholds; never left to model inference",
     "output": "Deterministic Rule Check pass/fail with the specific CFR subsection cited where applicable",
     "risk": "A stale threshold value produces a systematically wrong check across every facility until corrected"
    },
    {
     "decision": "Is this Compliance File ready to deliver, or does it need TEO Attorney / Healthcare CPA escalation?",
     "who": "AI drafts and scores confidence, Compliance Analyst confirms, escalation criteria route automatically",
     "inputs": "Drafted finding, confidence score, AGB tie-out result, novelty of correction-and-disclosure fact pattern",
     "rule": "Any of: confidence below threshold, an AGB tie-out discrepancy, an unrepresented fact pattern, or an active IRS examination — routes to the TEO Attorney or Healthcare CPA regardless of how routine the case otherwise looks",
     "output": "Delivered Compliance File or an escalated case with a logged reason",
     "risk": "Under-escalation delivers a file that should have had licensed judgment; over-escalation burns TEO Attorney/Healthcare CPA capacity on routine cases"
    }
   ],
   "events": [
    {
     "event": "ComplianceEngagementSubmitted",
     "meaning": "A facility policy/remittance/CHNA intake package is received and ready for a completeness check",
     "trigger": "Facility submits via secure upload or email",
     "downstream": [
      "Facility Intake completeness check",
      "Requirement Diff queue entry"
     ]
    },
    {
     "event": "RequirementDiffDrafted",
     "meaning": "The AI engine has classified the facility against the current requirement corpus and produced a first-pass finding, citations, and confidence score",
     "trigger": "Classification & drafting step completes",
     "downstream": "Enters the Compliance Analyst review queue"
    }
   ]
  },
  "subdomains": [
   {
    "name": "Requirement Compliance",
    "type": "core",
    "description": "Policy classification against the 26 CFR 1.501(r) checklist (the Requirement Diff), AGB Workpaper computation, and Compliance File drafting.",
    "reason": "This is the paid outcome's first gate — the requirement-by-requirement verdict determines everything downstream.",
    "business_value": "Direct revenue driver; every priced engagement starts here.",
    "recommendation": "Build in-house, deterministic-rules-first.",
    "ai_involvement": "Extraction, classification, drafting, confidence scoring",
    "human_involvement": "Compliance Analyst review and approval of every draft",
    "risks": [
     "Misclassified requirement causing a wrong finding",
     "Incomplete facts causing an analyst-caught gap"
    ],
    "validation_questions": [
     "What is the real analyst review time per Compliance File at volume?"
    ]
   },
   {
    "name": "Sign-Off & Escalation",
    "type": "core",
    "description": "Compliance Analyst sign-off, Exception Queue triage, and TEO Attorney / Healthcare CPA escalation and dual sign-off.",
    "reason": "Differentiates FacilityFile from a facility DIY-ing a chatbot check — this is the human-and-two-licensed-professionals discipline layer.",
    "business_value": "Drives the zero-material-examiner-finding north-star metric and the Remediation & Defense revenue line.",
    "recommendation": "Build in-house; maintain the escalation matrix from day one.",
    "ai_involvement": "Escalation-triage scoring",
    "human_involvement": "Compliance Analyst approves every finding; TEO Attorney and Healthcare CPA sign escalated/final determinations",
    "risks": [
     "Missed escalation on a genuinely novel correction-and-disclosure case",
     "Dual-signer bottleneck at volume"
    ],
    "validation_questions": [
     "How often does an escalated case actually change the AI-drafted finding?"
    ]
   },
   {
    "name": "Portfolio Compliance",
    "type": "core",
    "description": "System Portfolio tracking, System Portfolio Review assembly, and CHNA-clock drift detection across a health system's full facility roster.",
    "reason": "This is the human-chokepoint moat that produces the switching-cost lock-in the business is built on.",
    "business_value": "Directly drives renewal and expansion revenue.",
    "recommendation": "Build thin tooling (auto-assembly from the evidence log); keep the final review entirely human.",
    "ai_involvement": "Auto-assembles the review from the evidence log and flags CHNA-clock drift",
    "human_involvement": "Compliance Analyst final review and spot-check before delivery",
    "risks": [
     "A staggered CHNA clock quietly slips past its 3-year deadline"
    ],
    "validation_questions": [
     "How much system-level pricing discount is needed to convert a multi-facility prospect?"
    ]
   },
   {
    "name": "Requirement Corpus",
    "type": "supporting",
    "description": "The versioned 26 CFR 1.501(r) checklist, IRM 4.70.1 reference, Schedule H instructions, and state charity-care overlay library.",
    "reason": "Supports every core subdomain; could become core as it matures into a licensable, multi-state data asset.",
    "business_value": "Compounding differentiation asset; reduces novel-drafting time per engagement over time.",
    "recommendation": "Build in-house; version every entry with an effective date and a confirming Compliance Analyst.",
    "ai_involvement": "Drafts overlay-currency flags for human confirmation",
    "human_involvement": "Compliance Analyst confirms every overlay update before it goes live",
    "risks": [
     "A stale overlay entry used in a live engagement"
    ],
    "validation_questions": [
     "How often does a state actually change its charity-care overlay per year?"
    ]
   }
  ],
  "core_domain_analysis": {
   "primary_core": "Requirement Compliance",
   "secondary_cores": [
    "Sign-Off & Escalation",
    "Portfolio Compliance"
   ],
   "supporting_may_become_core": [
    "Requirement Corpus"
   ],
   "generic_do_not_distract": [
    "Referral & Outreach",
    "CRM/pipeline tracking"
   ],
   "rationale": "The paid outcome is a correctly classified, analyst-reviewed, and dual-signed Compliance File, so Requirement Compliance is the primary core. Sign-Off & Escalation and Portfolio Compliance are secondary cores because the human-plus-two-licensed-professionals discipline and the evidence-log/subscription lock-in are the moat that differentiates FacilityFile from a self-serve chatbot check or a full law-firm-plus-CPA-consultant bundle. The Requirement Corpus could become core as it matures into a licensable, multi-state data asset, but starts as supporting. Referral & Outreach uses off-the-shelf tooling deliberately to keep engineering focus on the compliance-production engine."
  },
  "bounded_contexts": [
   {
    "name": "Intake",
    "purpose": "Turn a facility's submitted compliance engagement and supporting facts into a normalized, completeness-checked ComplianceEngagement record ready for classification.",
    "subdomain": "Determination (core)",
    "type": "core",
    "owned_language": [
     "Compliance Engagement",
     "Facility Readiness Scan"
    ],
    "owns": [
     "Compliance Engagement request intake lifecycle",
     "Normalization state",
     "Required-fact completeness"
    ],
    "does_not_own": [
     "Requirement Corpus classification",
     "Analyst sign-off"
    ],
    "primary_actors": [
     "CFO / Compliance Officer",
     "Extraction Agent"
    ],
    "entities": [
     "ComplianceEngagement"
    ],
    "value_objects": [
     "ConfidenceScore",
     "DocumentsReceived"
    ],
    "aggregates": [
     "ComplianceEngagementAggregate"
    ],
    "domain_services": [
     "Request normalizer",
     "Completeness checker"
    ],
    "application_services": [
     "SubmitComplianceEngagement",
     "NormalizeRequestData",
     "CheckIntakeCompleteness"
    ],
    "commands": [
     "SubmitComplianceEngagement",
     "NormalizeRequestData"
    ],
    "domain_events": [
     "compliance engagement.request_submitted",
     "request.data_normalized",
     "request.completeness_check_failed"
    ],
    "policies": [
     "Auto-flag a missing required fact or document against the request type's evidence checklist"
    ],
    "specifications": [
     "RequiredEvidenceCompletenessSpec"
    ],
    "invariants": [
     "A ComplianceEngagement cannot proceed to classification until its required-evidence checklist is satisfied or a named exception is logged"
    ],
    "ai_agents": [
     "Extraction Agent"
    ],
    "human_roles": [
     "CFO / Compliance Officer"
    ],
    "data_owned": [
     "ComplianceEngagement"
    ],
    "inputs": [
     "Compliance Engagement description, amount, and payee",
     "Facility benefit-status confirmation",
     "Prior CHNA record and facility roster"
    ],
    "outputs": [
     "Normalized canonical compliance engagement-request record"
    ],
    "external_integrations": [
     "Monitored intake mailbox",
     "Secure upload form"
    ],
    "risks": [
     "A malformed submission silently mis-extracted",
     "Missing evidence for the request type goes unnoticed"
    ],
    "interfaces": [
     "-> Determination (RequestDataNormalized)"
    ]
   },
   {
    "name": "Determination",
    "purpose": "Run Deterministic Rule Checks, classify the request against the Requirement Corpus, and draft the Compliance File with citations and a confidence score.",
    "subdomain": "Determination (core)",
    "type": "core",
    "owned_language": [
     "Compliance File",
     "Requirement Diff",
     "Deterministic Rule Check",
     "Correction Pathway"
    ],
    "owns": [
     "Classification engine",
     "Deterministic Rule Check execution",
     "Determination drafting"
    ],
    "does_not_own": [
     "Analyst identity",
     "Billing"
    ],
    "primary_actors": [
     "Compliance Analyst",
     "Classification Agent"
    ],
    "entities": [
     "ComplianceFile"
    ],
    "value_objects": [
     "ConfidenceScore",
     "BenefitImpactAmount"
    ],
    "aggregates": [
     "ComplianceFileAggregate"
    ],
    "domain_services": [
     "Classification engine",
     "Deterministic Rule Check engine"
    ],
    "application_services": [
     "RunBrightLineChecks",
     "ClassifyAndDraftDetermination"
    ],
    "commands": [
     "RunBrightLineChecks",
     "ClassifyAndDraftDetermination"
    ],
    "domain_events": [
     "brightline.check_completed",
     "determination.drafted",
     "determination.confidence_scored"
    ],
    "policies": [
     "Auto-route confidence below threshold to the Exception Queue regardless of dollar value"
    ],
    "specifications": [
     "RequiredEvidenceCompletenessSpec",
     "CitationRequiredSpec"
    ],
    "invariants": [
     "A Deterministic Rule Check result is never overridden by AI classification",
     "No dollar figure in a Compliance File is ever LLM-computed"
    ],
    "ai_agents": [
     "Classification Agent",
     "Drafting Agent"
    ],
    "human_roles": [
     "Compliance Analyst"
    ],
    "data_owned": [
     "ComplianceFile"
    ],
    "inputs": [
     "Normalized compliance engagement-request data",
     "Requirement Corpus"
    ],
    "outputs": [
     "Draft Compliance File with citations and confidence score"
    ],
    "external_integrations": [
     "Requirement Corpus (internal)"
    ],
    "risks": [
     "Misclassification against a stale Requirement Corpus version",
     "An unsupported citation reaching the analyst queue"
    ],
    "interfaces": [
     "-> Review & Escalation (DeterminationDrafted)"
    ]
   },
   {
    "name": "Review & Escalation",
    "purpose": "Enforce 100% analyst review, triage the Exception Queue, and route novel/high-value/low-confidence/TEO Attorney Determination cases to the attorney bench for sign-off.",
    "subdomain": "Review & Escalation (core)",
    "type": "core",
    "owned_language": [
     "Exception Queue",
     "TEO Attorney Determination",
     "Compliance Analyst"
    ],
    "owns": [
     "Review queue",
     "Escalation triggers",
     "Attorney sign-off lifecycle"
    ],
    "does_not_own": [
     "Classification logic (upstream)"
    ],
    "primary_actors": [
     "Compliance Analyst",
     "TEO Attorney"
    ],
    "entities": [
     "ComplianceFile",
     "EscalationCase"
    ],
    "value_objects": [
     "EscalationReasonCode",
     "ReviewStatus"
    ],
    "aggregates": [
     "EscalationCaseAggregate"
    ],
    "domain_services": [
     "Escalation triage engine"
    ],
    "application_services": [
     "ReviewDeterminationDraft",
     "EscalateToAttorneyBench",
     "SignDetermination",
     "DeliverComplianceFile"
    ],
    "commands": [
     "EscalateToAttorneyBench",
     "SignDetermination",
     "DeliverComplianceFile"
    ],
    "domain_events": [
     "determination.analyst_reviewed",
     "RequestEscalated",
     "DeterminationSigned",
     "DeterminationDelivered"
    ],
    "policies": [
     "100% of drafted determinations require analyst review before delivery, no exceptions",
     "Every TEO Attorney Determination requires attorney sign-off before delivery"
    ],
    "specifications": [
     "EscalationCriteriaSpec"
    ],
    "invariants": [
     "A Compliance File cannot be delivered without at least one Compliance Analyst sign-off",
     "A TEO Attorney Determination cannot be delivered without a licensed attorney's signature"
    ],
    "ai_agents": [
     "Escalation-Triage Agent"
    ],
    "human_roles": [
     "Compliance Analyst",
     "TEO Attorney"
    ],
    "data_owned": [
     "EscalationCase"
    ],
    "inputs": [
     "Draft Compliance File",
     "Escalation criteria thresholds"
    ],
    "outputs": [
     "Analyst-approved or attorney-signed Compliance File, delivered"
    ],
    "external_integrations": [
     "Contracted attorney bench (e-signature)"
    ],
    "risks": [
     "Under-escalation of a genuinely novel case",
     "Attorney-bench turnaround bottleneck at volume"
    ],
    "interfaces": [
     "-> Portfolio Compliance (DeterminationDelivered)",
     "-> Requirement Corpus (DeterminationOutcomeLogged)"
    ]
   },
   {
    "name": "Portfolio Compliance",
    "purpose": "Track Annual Compliance File subscription accounts, assemble the System Portfolio Review, and detect drift across a facility's full compliance portfolio.",
    "subdomain": "Portfolio Compliance (core)",
    "type": "core",
    "owned_language": [
     "Annual Compliance File subscription",
     "System Portfolio Review",
     "Evidence List"
    ],
    "owns": [
     "Retainer lifecycle",
     "Quarterly review assembly",
     "Drift detection"
    ],
    "does_not_own": [
     "Individual determination drafting (upstream)"
    ],
    "primary_actors": [
     "Compliance Analyst",
     "Portfolio Drift-Detection Agent"
    ],
    "entities": [
     "PortfolioReview"
    ],
    "value_objects": [
     "DriftScore"
    ],
    "aggregates": [
     "PortfolioReviewAggregate"
    ],
    "domain_services": [
     "Portfolio drift detector",
     "Review assembler"
    ],
    "application_services": [
     "RunQuarterlyPortfolioReview",
     "TrackRetainerUsage"
    ],
    "commands": [
     "RunQuarterlyPortfolioReview"
    ],
    "domain_events": [
     "PortfolioDriftDetected",
     "portfolio_review.assembled"
    ],
    "policies": [
     "Any portfolio-level pattern crossing a defined drift threshold is flagged even if each underlying determination looked fine individually"
    ],
    "specifications": [
     "PortfolioReviewCompletenessSpec"
    ],
    "invariants": [
     "A System Portfolio Review cannot be delivered without Compliance Analyst final review"
    ],
    "ai_agents": [
     "Portfolio Drift-Detection Agent"
    ],
    "human_roles": [
     "Compliance Analyst"
    ],
    "data_owned": [
     "PortfolioReview"
    ],
    "inputs": [
     "Full determination history for a facility's portfolio"
    ],
    "outputs": [
     "Delivered System Portfolio Review with flagged drift patterns"
    ],
    "external_integrations": [
     "Facility case-management export (as needed)"
    ],
    "risks": [
     "A drift pattern missed if review scope excludes older determinations"
    ],
    "interfaces": [
     "-> Requirement Corpus (RuleMatrixVersionPublished consumed)"
    ]
   },
   {
    "name": "Requirement Corpus",
    "purpose": "Maintain the per-jurisdiction (federal 26 CFR 1.501(r), state IRS-supplement, CHNA QDE) versioned rule set and citation anchors used by every other context.",
    "subdomain": "Requirement Corpus (supporting)",
    "type": "supporting",
    "owned_language": [
     "Requirement Corpus",
     "Requirement Corpus Version"
    ],
    "owns": [
     "Jurisdiction rule sets",
     "Citation anchors",
     "Change-monitoring log"
    ],
    "does_not_own": [
     "Determination decisions"
    ],
    "primary_actors": [
     "TEO Attorney"
    ],
    "entities": [
     "RuleMatrixEntry"
    ],
    "value_objects": [
     "RuleVersionTag",
     "CitationAnchor"
    ],
    "aggregates": [
     "RuleMatrixVersionAggregate"
    ],
    "domain_services": [
     "Rule set updater",
     "Change-diff detector"
    ],
    "application_services": [
     "UpdateRuleMatrix"
    ],
    "commands": [
     "UpdateRuleMatrix"
    ],
    "domain_events": [
     "RuleMatrixVersionPublished"
    ],
    "policies": [
     "Quarterly attorney-reviewed re-verification of every active jurisdiction's rules"
    ],
    "specifications": [
     "RuleMatrixFreshnessSpec"
    ],
    "invariants": [
     "Every rule entry carries a source citation and a last-confirmed date"
    ],
    "ai_agents": [],
    "human_roles": [
     "TEO Attorney"
    ],
    "data_owned": [
     "RuleMatrixEntry"
    ],
    "inputs": [
     "IRS 26 CFR 1.501(r) updates",
     "State IRS-supplement rule changes",
     "IRS/IRS CHNA QDE guidance updates"
    ],
    "outputs": [
     "Updated per-jurisdiction rule profiles"
    ],
    "external_integrations": [],
    "risks": [
     "Stale rule applied after a regulatory update"
    ],
    "interfaces": [
     "<- Review & Escalation (DeterminationOutcomeLogged)",
     "<- Portfolio Compliance (PortfolioDriftDetected)"
    ]
   }
  ],
  "context_map": [
   {
    "upstream": "Intake",
    "downstream": "Determination",
    "relationship": "Customer-Supplier",
    "integration_pattern": "Domain event (RequestDataNormalized) consumed by the classification engine",
    "translation_notes": "Canonical compliance engagement-request schema is the shared contract; no direct database coupling.",
    "pattern": "Customer-Supplier",
    "contract_type": "domain event",
    "data_exchanged": [
     "[PLACEHOLDER] owner to complete"
    ],
    "events_exchanged": [
     "Domain event (RequestDataNormalized) consumed by the classification engine"
    ],
    "ownership_boundary": "Downstream never writes to upstream's tables",
    "acl_notes": "Anti-corruption translation not needed — shared canonical schema",
    "business_reason": "Keeps each context's invariants enforceable independently",
    "failure_risks": [
     "[PLACEHOLDER] owner to complete"
    ]
   },
   {
    "upstream": "Determination",
    "downstream": "Review & Escalation",
    "relationship": "Customer-Supplier",
    "integration_pattern": "Domain event (DeterminationDrafted) triggers analyst review",
    "translation_notes": "Only classified, cited drafts cross the boundary.",
    "pattern": "Customer-Supplier",
    "contract_type": "domain event",
    "data_exchanged": "Canonical schema payload only",
    "events_exchanged": [
     "Domain event (DeterminationDrafted) triggers analyst review"
    ],
    "ownership_boundary": "Downstream never writes to upstream's tables",
    "acl_notes": "Anti-corruption translation not needed — shared canonical schema",
    "business_reason": "Keeps each context's invariants enforceable independently",
    "failure_risks": "Downstream stalls if upstream event delivery fails"
   },
   {
    "upstream": "Review & Escalation",
    "downstream": "Portfolio Compliance",
    "relationship": "Customer-Supplier",
    "integration_pattern": "Domain event (DeterminationDelivered) feeds the portfolio review",
    "translation_notes": "Only fully delivered determinations enter the portfolio history.",
    "pattern": "Customer-Supplier",
    "contract_type": "domain event",
    "data_exchanged": "Canonical schema payload only",
    "events_exchanged": [
     "Domain event (DeterminationDelivered) feeds the portfolio review"
    ],
    "ownership_boundary": "Downstream never writes to upstream's tables",
    "acl_notes": "Anti-corruption translation not needed — shared canonical schema",
    "business_reason": "Keeps each context's invariants enforceable independently",
    "failure_risks": "Portfolio review stalls if a delivery event is dropped"
   },
   {
    "upstream": "Requirement Corpus",
    "downstream": "Determination",
    "relationship": "Shared Kernel (published language)",
    "integration_pattern": "Versioned rule-set read (thresholds, citation anchors, jurisdiction coverage)",
    "translation_notes": "Determination reads the current Requirement Corpus version; never writes to it directly.",
    "pattern": "Conformist",
    "contract_type": "published schema",
    "data_exchanged": "Requirement Corpus entries (thresholds, citations)",
    "events_exchanged": [
     "RuleMatrixVersionPublished"
    ],
    "ownership_boundary": "Determination never writes to the Requirement Corpus",
    "acl_notes": "None needed — Requirement Corpus is the canonical source",
    "business_reason": "One place to update a regulatory change so every context stays consistent",
    "failure_risks": "Stale rule version used if the update event is missed"
   }
  ],
  "external_integrations": [
   {
    "system": "Secure intake portal/email",
    "direction": "inbound",
    "pattern": "manual upload/email (cycle 1+), no live IRS API integration at launch",
    "risk": "Malformed or incomplete submission format",
    "owner_context": "Intake",
    "data_in": [
     "[PLACEHOLDER] owner to complete"
    ],
    "data_out": [
     "[PLACEHOLDER] owner to complete"
    ],
    "trigger": "Every new Compliance Engagement",
    "internal_model": "Canonical compliance engagement-request schema",
    "acl_strategy": "Parser + LLM normalization layer translates any submission format to the canonical schema",
    "failure_strategy": "Malformed submission routes to the exception queue with a named parsing gap",
    "audit_need": "Every submission state observed is timestamped in the Evidence List"
   },
   {
    "system": "E-signature tool (attorney sign-off)",
    "direction": "outbound",
    "pattern": "signature request on every escalated/certified determination",
    "risk": "Signature not captured before delivery",
    "owner_context": "Review & Escalation",
    "data_in": "None",
    "data_out": "Compliance File for signature",
    "trigger": "Escalation or TEO Attorney Determination request",
    "internal_model": "EscalationCase",
    "acl_strategy": "Direct e-signature API integration",
    "failure_strategy": "Delivery blocked pending a captured signature",
    "audit_need": "Signature manifest retained with the delivered memo"
   },
   {
    "system": "Lightweight CRM (pipeline/renewal tracking)",
    "direction": "bidirectional",
    "pattern": "off-the-shelf tool, not built in-house",
    "risk": "Low differentiation risk if under-invested",
    "owner_context": "Referral & Outreach",
    "data_in": "Prospect and account contact data",
    "data_out": "None sensitive",
    "trigger": "Outreach and renewal cadence",
    "internal_model": "N/A — external tool",
    "acl_strategy": "Standard CRM integration, no facility data stored here",
    "failure_strategy": "Manual pipeline tracking fallback",
    "audit_need": "None — no sensitive data in this system"
   },
   {
    "system": "OCR/document-extraction tool (near-term addition)",
    "direction": "inbound",
    "pattern": "receipt/invoice ingestion to support extraction",
    "risk": "OCR misread on a poor-quality scan",
    "owner_context": "Intake",
    "data_in": "Receipt/invoice images or PDFs",
    "data_out": "None",
    "trigger": "Compliance Engagement request with supporting documents",
    "internal_model": "Canonical compliance engagement-request schema",
    "acl_strategy": "OCR output routed through the same confidence-scored extraction layer as manual entry",
    "failure_strategy": "Low-confidence OCR output routes to analyst confirmation",
    "audit_need": "Original document retained alongside the extracted record"
   }
  ],
  "event_storm": [
   {
    "seq": 1,
    "command": "SubmitComplianceEngagement",
    "event": "compliance engagement.request_submitted",
    "actor": "CFO / Compliance Officer",
    "context": "Intake",
    "aggregate": "ComplianceEngagement",
    "policy": "Completeness checklist auto-enforced before any review starts",
    "downstream": "Normalization begins",
    "risk": "Incomplete request data blocks the compliance check"
   },
   {
    "seq": 2,
    "command": "NormalizeRequestData",
    "event": "request.data_normalized",
    "actor": "Extraction Agent",
    "context": "Intake",
    "aggregate": "ComplianceEngagement",
    "policy": "Confidence-scored field extraction; below-threshold fields flagged",
    "downstream": "Classification begins",
    "risk": "Malformed submission silently mis-extracted"
   },
   {
    "seq": 3,
    "command": "RunBrightLineChecks",
    "event": "brightline.check_completed",
    "actor": "Deterministic rule engine",
    "context": "Determination",
    "aggregate": "ComplianceFile",
    "policy": "Resource-limit/AGB/CHNA-cap checks run in code, never model-inferred",
    "downstream": "AI classification proceeds with the Deterministic-Rule result as a hard constraint",
    "risk": "A stale threshold value produces a systematically wrong check"
   },
   {
    "seq": 4,
    "command": "ClassifyAndDraftDetermination",
    "event": "determination.drafted",
    "actor": "Classification Agent / Drafting Agent",
    "context": "Determination",
    "aggregate": "ComplianceFile",
    "policy": "Confidence below threshold forces Exception Queue routing",
    "downstream": "Analyst review queue",
    "risk": "Misclassification against a stale Requirement Corpus version"
   },
   {
    "seq": 5,
    "command": "ReviewDeterminationDraft / EscalateToAttorneyBench",
    "event": "determination.analyst_reviewed / RequestEscalated",
    "actor": "Compliance Analyst",
    "context": "Review & Escalation",
    "aggregate": "EscalationCase",
    "policy": "100% human approval on every determination, no exceptions",
    "downstream": "Determination approved, or escalated to the attorney bench",
    "risk": "Under-escalation of a genuinely novel case"
   },
   {
    "seq": 6,
    "command": "SignDetermination / DeliverComplianceFile",
    "event": "DeterminationSigned / DeterminationDelivered",
    "actor": "TEO Attorney / Compliance Analyst",
    "context": "Review & Escalation",
    "aggregate": "EscalationCase",
    "policy": "TEO Attorney Determination requires attorney signature before delivery",
    "downstream": "Portfolio Compliance logs the delivered determination",
    "risk": "A signed-but-uncommunicated escalation delays delivery past the SLA"
   }
  ],
  "critical_path": [
   "Intake -> Determination -> Review & Escalation (analyst or attorney sign-off) -> Portfolio Compliance, gated by a Compliance Analyst sign-off on every delivery"
  ],
  "exception_flows": [
   "A classification scores below the confidence threshold -> routed to the Exception Queue for attorney escalation before any memo is delivered",
   "A required fact (e.g., facility's current benefit-status confirmation) is missing -> blocked from classification and logged as a named exception until the facility supplies it"
  ],
  "escalation_flows": [
   "A Deterministic Rule Check fails (excise-tax threshold, AGB formula, CHNA cap) -> forces a do-not-disburse or approve-with-conditions draft with a mandatory Correction Pathway attempt",
   "A dispute or novel legal question that could reach litigation -> hard stop at a documented Compliance File, referred to the facility's own counsel; FacilityFile does not advocate legally"
  ],
  "retry_flows": [
   "An incomplete request with no facility response after 2 business days triggers an automated follow-up request, held for analyst visibility"
  ],
  "manual_override_flows": [
   "A Compliance Analyst may manually reclassify a request's purpose category when new facts change the correct Requirement Corpus citation"
  ],
  "commands": [
   {
    "name": "SubmitComplianceEngagement",
    "issued_by": "CFO / Compliance Officer",
    "preconditions": [
     "Engagement letter signed",
     "Request facts supplied"
    ],
    "aggregate": "ComplianceEngagement",
    "success_event": "compliance engagement.request_submitted",
    "failure_event": "request.rejected_incomplete",
    "authorization": "Facility-authorized submission only",
    "validation": "Completeness checklist",
    "audit": "Intake timestamp + submitted-fact manifest logged"
   },
   {
    "name": "NormalizeRequestData",
    "issued_by": "Extraction Agent (analyst confirms below threshold)",
    "preconditions": [
     "Request submitted"
    ],
    "aggregate": "ComplianceEngagement",
    "success_event": "request.data_normalized",
    "failure_event": "request.extraction_below_threshold",
    "authorization": "System; analyst required below confidence threshold",
    "validation": "ConfidenceScore >= threshold or analyst sign-off",
    "audit": "Extraction rationale + confidence score logged"
   },
   {
    "name": "RunBrightLineChecks",
    "issued_by": "Deterministic rule engine",
    "preconditions": [
     "Request data normalized"
    ],
    "aggregate": "ComplianceFile",
    "success_event": "brightline.check_completed",
    "failure_event": "brightline.check_blocked_missing_data",
    "authorization": "System only — no human or AI override",
    "validation": "Deterministic-Rule thresholds from the current Requirement Corpus version",
    "audit": "Check result + rule version logged per request"
   },
   {
    "name": "ClassifyAndDraftDetermination",
    "issued_by": "Classification Agent / Drafting Agent",
    "preconditions": [
     "Deterministic Rule Checks completed"
    ],
    "aggregate": "ComplianceFile",
    "success_event": "determination.drafted",
    "failure_event": "determination.drafting_failed",
    "authorization": "System; analyst review required before delivery regardless of outcome",
    "validation": "CitationRequiredSpec — every claim must cite a source",
    "audit": "Draft + citations + confidence score logged"
   },
   {
    "name": "EscalateToAttorneyBench",
    "issued_by": "Compliance Analyst / automatic escalation rule",
    "preconditions": [
     "Escalation criteria met (novel/high-value/low-confidence/certified)"
    ],
    "aggregate": "EscalationCase",
    "success_event": "RequestEscalated",
    "failure_event": "escalation.blocked_no_available_attorney",
    "authorization": "Analyst or automatic rule trigger",
    "validation": "EscalationCriteriaSpec",
    "audit": "Escalation reason + timestamp logged"
   },
   {
    "name": "DeliverComplianceFile",
    "issued_by": "Compliance Analyst (attorney co-signs on escalated/certified cases)",
    "preconditions": [
     "Analyst sign-off recorded",
     "Attorney sign-off recorded if escalated"
    ],
    "aggregate": "EscalationCase",
    "success_event": "DeterminationDelivered",
    "failure_event": "delivery.blocked_missing_signoff",
    "authorization": "Analyst sign-off required; attorney sign-off required for escalated/certified cases",
    "validation": "Full citation + signature manifest present",
    "audit": "Delivered memo + signature manifest retained"
   }
  ],
  "policies": [
   {
    "name": "Deterministic-Rule resource-limit gate",
    "trigger": "A compliance engagement would leave the facility holding more than $50,000 in compliant reserves",
    "condition": "Deterministic check against current compliant reserves plus the proposed compliance engagement's effect",
    "action": "Force a do-not-disburse or approve-with-conditions verdict with a mandatory Correction Pathway attempt",
    "context": "Determination",
    "ai_involvement": "None — deterministic code only",
    "human_approval": false
   },
   {
    "name": "Low-confidence escalation",
    "trigger": "A determination is drafted",
    "condition": "ConfidenceScore below the defined threshold",
    "action": "Route automatically to the attorney bench regardless of dollar value",
    "context": "Determination",
    "ai_involvement": "Propose classification + confidence score",
    "human_approval": true
   },
   {
    "name": "100%-analyst-review requirement",
    "trigger": "Any determination is drafted",
    "condition": "Always",
    "action": "No Compliance File is delivered without a Compliance Analyst's recorded sign-off",
    "context": "Review & Escalation",
    "ai_involvement": "Draft only",
    "human_approval": true
   },
   {
    "name": "TEO Attorney Determination attorney sign-off",
    "trigger": "A TEO Attorney Determination is requested",
    "condition": "Always",
    "action": "Route to the attorney bench; block delivery until a licensed attorney signs",
    "context": "Review & Escalation",
    "ai_involvement": "Draft only",
    "human_approval": true
   }
  ],
  "aggregates": [
   {
    "name": "ComplianceEngagementAggregate",
    "root": "ComplianceEngagement",
    "context": "Intake",
    "purpose": "Represents one proposed 501(r) expenditure and its supporting facts prior to classification.",
    "entities": [
     "SupportingDocument"
    ],
    "value_objects": [
     "ConfidenceScore",
     "DocumentsReceived"
    ],
    "invariants": [
     "A ComplianceEngagement cannot advance to Determination until required facts are present or exception-logged"
    ],
    "commands": [
     "SubmitComplianceEngagement",
     "NormalizeRequestData"
    ],
    "events": [
     "compliance engagement.request_submitted",
     "request.data_normalized"
    ],
    "repository": "ComplianceEngagementRepository (per-facility partitioned)",
    "transaction_boundary": "One request per commit"
   },
   {
    "name": "ComplianceFileAggregate",
    "root": "ComplianceFile",
    "context": "Determination",
    "purpose": "Represents one drafted-through-delivered compliance verdict for a Compliance Engagement, its citations, and its Requirement Diff.",
    "entities": [
     "Citation"
    ],
    "value_objects": [
     "ConfidenceScore",
     "BenefitImpactAmount"
    ],
    "invariants": [
     "A Deterministic Rule Check result is never overridden by AI classification",
     "No dollar figure is ever LLM-computed"
    ],
    "commands": [
     "RunBrightLineChecks",
     "ClassifyAndDraftDetermination"
    ],
    "events": [
     "brightline.check_completed",
     "determination.drafted"
    ],
    "repository": "ComplianceFileRepository (per-facility partitioned)",
    "transaction_boundary": "One ComplianceFile per commit"
   },
   {
    "name": "EscalationCaseAggregate",
    "root": "EscalationCase",
    "context": "Review & Escalation",
    "purpose": "Represents one determination's review-and-sign-off lifecycle, including any attorney escalation.",
    "entities": [
     "SignatureRecord"
    ],
    "value_objects": [
     "EscalationReasonCode"
    ],
    "invariants": [
     "A Compliance File cannot be delivered without an analyst sign-off",
     "A TEO Attorney Determination cannot be delivered without an attorney signature"
    ],
    "commands": [
     "EscalateToAttorneyBench",
     "SignDetermination",
     "DeliverComplianceFile"
    ],
    "events": [
     "RequestEscalated",
     "DeterminationSigned",
     "DeterminationDelivered"
    ],
    "repository": "EscalationCaseRepository (per-facility partitioned)",
    "transaction_boundary": "One EscalationCase per commit"
   },
   {
    "name": "PortfolioReviewAggregate",
    "root": "PortfolioReview",
    "context": "Portfolio Compliance",
    "purpose": "Represents one facility's quarterly, full-portfolio compliance sweep and any detected drift.",
    "entities": [
     "DriftFinding"
    ],
    "value_objects": [
     "DriftScore"
    ],
    "invariants": [
     "A System Portfolio Review cannot be delivered without analyst final review"
    ],
    "commands": [
     "RunQuarterlyPortfolioReview"
    ],
    "events": [
     "PortfolioDriftDetected",
     "portfolio_review.assembled"
    ],
    "repository": "PortfolioReviewRepository (per-facility partitioned)",
    "transaction_boundary": "One PortfolioReview per facility per quarter"
   },
   {
    "name": "RuleMatrixVersionAggregate",
    "root": "RuleMatrixVersion",
    "context": "Requirement Corpus",
    "purpose": "Represents one versioned snapshot of the federal/state/CHNA rule set with citation anchors.",
    "entities": [
     "RuleEntry"
    ],
    "value_objects": [
     "RuleVersionTag",
     "CitationAnchor"
    ],
    "invariants": [
     "Every rule entry carries a source citation and a last-confirmed date"
    ],
    "commands": [
     "UpdateRuleMatrix"
    ],
    "events": [
     "RuleMatrixVersionPublished"
    ],
    "repository": "RuleMatrixRepository (shared, read by all facilities)",
    "transaction_boundary": "One rule version per commit"
   }
  ],
  "ai_agents": [
   {
    "name": "Extraction Agent",
    "context": "Intake",
    "responsibility": "Parses compliance engagement-request submissions of any format into the canonical schema.",
    "inputs": [
     "Compliance Engagement request description, amount, payee",
     "Supporting receipts/invoices"
    ],
    "outputs": [
     "Normalized canonical records with a per-field confidence score"
    ],
    "tools": [
     "Python parsers",
     "Frontier LLM API for unstructured-format extraction"
    ],
    "forbidden_actions": [
     "Never stores or requests a facility/family credential",
     "Never computes a final dollar figure used in a memo"
    ],
    "memory_scope": "Per-facility, per-request; no cross-facility memory",
    "retrieval_sources": [
     "Requirement Corpus field-mapping conventions"
    ],
    "validations": [
     "Completeness checklist per request type"
    ],
    "confidence_scoring": "Per-field confidence score; below-threshold fields routed to analyst confirmation",
    "escalation_triggers": [
     "Confidence below 70% on a required field"
    ],
    "human_approval": "Not required for normalization itself; required before any downstream delivery",
    "failure_modes": [
     "Silent mis-extraction of a malformed submission",
     "OCR misread on a poor-quality scan"
    ],
    "audit_logs": [
     "Intake timestamp + submitted-fact manifest + extraction confidence scores"
    ],
    "metrics": [
     "Extraction accuracy vs. gold-standard sample",
     "Time to normalized output"
    ],
    "versioning": "Prompt + parser version pinned per Requirement Corpus release"
   },
   {
    "name": "Classification Agent",
    "context": "Determination",
    "responsibility": "Classifies the normalized request against the current Requirement Corpus and computes a Requirement Diff.",
    "inputs": [
     "Normalized compliance engagement-request record",
     "Requirement Corpus"
    ],
    "outputs": [
     "Classification with cited rationale and confidence score",
     "Requirement Diff"
    ],
    "tools": [
     "Frontier LLM API",
     "Deterministic Rule Check engine"
    ],
    "forbidden_actions": [
     "Never overrides a Deterministic Rule Check result",
     "Never computes a dollar figure outside deterministic code"
    ],
    "memory_scope": "Per-facility, per-request; prior determination history retained for pattern learning",
    "retrieval_sources": [
     "Requirement Corpus",
     "Prior determination history for the same facility"
    ],
    "validations": [
     "ConfidenceScore >= threshold or analyst sign-off"
    ],
    "confidence_scoring": "Fact-pattern-match confidence band against the adjudicated-example library",
    "escalation_triggers": [
     "Confidence below 70%",
     "Fact pattern not represented in the adjudicated-example library"
    ],
    "human_approval": "Required below the confidence threshold and on every delivery",
    "failure_modes": [
     "Misclassification against a stale Requirement Corpus version",
     "Missed jurisdiction-specific nuance"
    ],
    "audit_logs": [
     "Classification rationale + cited rule + confidence score per request"
    ],
    "metrics": [
     "Auto-classification accuracy vs. gold-standard sample",
     "Escalation rate per 100 requests"
    ],
    "versioning": "Prompt + rules version pinned per Requirement Corpus release"
   },
   {
    "name": "Drafting Agent",
    "context": "Determination",
    "responsibility": "Assembles the Compliance File narrative citing the classification result and, where applicable, a Correction Pathway.",
    "inputs": [
     "Classification result with citations",
     "Requirement Corpus citation set"
    ],
    "outputs": [
     "Draft Compliance File with cited evidence"
    ],
    "tools": [
     "Frontier LLM API",
     "Citation-linked retrieval over the Requirement Corpus"
    ],
    "forbidden_actions": [
     "Never asserts a dollar amount not computed deterministically",
     "Never implies certainty about a future IRS finding"
    ],
    "memory_scope": "Per-facility, per-determination",
    "retrieval_sources": [
     "Requirement Corpus citation anchors"
    ],
    "validations": [
     "CitationRequiredSpec — every claim in the memo must cite a source"
    ],
    "confidence_scoring": "Memo flagged for analyst rewrite if a required citation is missing",
    "escalation_triggers": [
     "Missing citation",
     "Dollar amount mismatch vs. deterministic computation"
    ],
    "human_approval": "Required before any memo reaches a facility",
    "failure_modes": [
     "Unsupported or overstated claim language"
    ],
    "audit_logs": [
     "Draft memo + citations + analyst signature retained"
    ],
    "metrics": [
     "Memo rejection rate",
     "Time from classification to drafted memo"
    ],
    "versioning": "Prompt version pinned per Requirement Corpus release"
   },
   {
    "name": "Escalation-Triage Agent",
    "context": "Review & Escalation",
    "responsibility": "Applies the escalation criteria in order and routes a determination to the attorney bench when triggered.",
    "inputs": [
     "Drafted determination",
     "Confidence score",
     "Escalation criteria thresholds"
    ],
    "outputs": [
     "Escalation decision with a logged reason"
    ],
    "tools": [
     "Deterministic escalation-rule engine"
    ],
    "forbidden_actions": [
     "Never suppresses a later-matching escalation reason once one is found",
     "Never de-escalates a case an analyst has flagged"
    ],
    "memory_scope": "Per-facility, per-determination",
    "retrieval_sources": [
     "Escalation criteria configuration"
    ],
    "validations": [
     "EscalationCriteriaSpec"
    ],
    "confidence_scoring": "N/A — deterministic rule application",
    "escalation_triggers": [
     "TEO Attorney Determination requested",
     "Confidence below threshold",
     "High-value threshold exceeded",
     "Novel fact pattern",
     "Governing-document change implicated"
    ],
    "human_approval": "Escalation itself is automatic; the resulting attorney review is always human",
    "failure_modes": [
     "Escalation-rule misconfiguration causing under- or over-escalation"
    ],
    "audit_logs": [
     "Escalation reason + timestamp logged per case"
    ],
    "metrics": [
     "Escalation rate",
     "Escalation-reason distribution"
    ],
    "versioning": "Escalation criteria versioned per Requirement Corpus release"
   },
   {
    "name": "Portfolio Drift-Detection Agent",
    "context": "Portfolio Compliance",
    "responsibility": "Scans a facility's full determination history for the System Portfolio Review and flags aggregate patterns that look risky only in combination.",
    "inputs": [
     "Full-portfolio determination history"
    ],
    "outputs": [
     "Draft drift findings with a completeness score"
    ],
    "tools": [
     "Deterministic pattern-detection rules",
     "Frontier LLM API for narrative summaries"
    ],
    "forbidden_actions": [
     "Never issues a final portfolio verdict without analyst review",
     "Never omits a required review section without a logged, named gap"
    ],
    "memory_scope": "Per-facility, per-review-cycle",
    "retrieval_sources": [
     "Full determination history for the facility"
    ],
    "validations": [
     "PortfolioReviewCompletenessSpec"
    ],
    "confidence_scoring": "Drift score per detected pattern",
    "escalation_triggers": [
     "Any high-severity drift pattern detected"
    ],
    "human_approval": "Required — final review and spot-check before delivery",
    "failure_modes": [
     "A drift pattern missed if review scope excludes older determinations"
    ],
    "audit_logs": [
     "Review manifest signed by the Compliance Analyst"
    ],
    "metrics": [
     "Review completeness score",
     "Review-cycle turnaround time"
    ],
    "versioning": "Review template versioned per program-year"
   }
  ],
  "prompt_chain_map": [
   "Extraction Agent (parse) -> Classification Agent (classify + score, after Deterministic Rule Checks) -> Drafting Agent (memo, only after classification) -> Compliance Analyst gate -> Escalation-Triage Agent (parallel, routes if triggered)",
   "Full determination history -> Portfolio Drift-Detection Agent (draft findings) -> Compliance Analyst final review -> delivered System Portfolio Review"
  ],
  "rag_map": [
   "Requirement Corpus (versioned federal 26 CFR 1.501(r) + state IRS-supplement + CHNA QDE guidance with citation anchors) retrieved by the Classification Agent and the Drafting Agent for every determination",
   "Prior determination history retrieved by the Portfolio Drift-Detection Agent, restricted to the requesting facility's own portfolio only"
  ],
  "ai_evaluation": [
   "Gold-standard adjudicated determination examples used for regression testing on every prompt or Requirement Corpus version change",
   "Monthly red-team run: seeded error requests (ambiguous AGB cases, borderline resource-limit cases, mixed 501(r) fact patterns) verify the engine catches known failure patterns",
   "5-10% sampled re-verification of standard-tier determinations against a manually re-checked baseline"
  ],
  "hallucination_controls": [
   "Retrieval-first classification and drafting — every claim cites a specific 26 CFR 1.501(r)/state-rule/CHNA QDE citation",
   "Deterministic Deterministic Rule Checks and all dollar arithmetic in code, never the model",
   "Confidence-scored classification with mandatory analyst confirmation below threshold",
   "CitationRequiredSpec rejects any memo missing a required citation",
   "Deterministic disclaimer injection prevents any memo from implying certainty about a future IRS finding"
  ],
  "human_in_the_loop_plan": [
   "Classification gate: no determination below the confidence threshold proceeds without analyst confirmation",
   "Delivery gate: every Compliance File is human-approved before it reaches a facility",
   "Certification gate: every TEO Attorney Determination and every escalated determination is attorney-signed",
   "Dual review on any TEO Attorney Determination above the defined high-value threshold"
  ],
  "ai_audit_plan": [
   "Every AI-drafted determination and every AI-proposed classification is logged with its confidence score and cited source before analyst review",
   "Quarterly gold-standard regression test against the current Requirement Corpus version",
   "Annual external review of the hallucination-control suite ahead of each state's legislative session"
  ],
  "prompt_versioning": "Prompts + schemas + the Requirement Corpus are model-agnostic and version-pinned together; a frontier-model swap is a config change, not a rebuild (see ai-engine-spec.md Model Portability).",
  "human_roles": [
   {
    "role": "Compliance Analyst",
    "responsibilities": [
     "Review every AI-drafted Requirement Diff finding and artifact before delivery to a licensed signer",
     "Approve every escalation decision",
     "Sign off on every System Portfolio Review"
    ],
    "contexts": [
     "Requirement Compliance",
     "Sign-Off & Escalation",
     "Portfolio Compliance"
    ],
    "decisions_owned": [
     "Finding confirmation or edit",
     "Escalation triage below automatic thresholds",
     "Portfolio drift-finding release"
    ],
    "ai_support": [
     "Confidence-scored draft findings with CFR citations"
    ],
    "approval_authority": "Sole approver for every Compliance Analyst completeness check; TEO Attorney and Healthcare CPA sign-off required on every final Compliance File",
    "escalation_authority": "Can escalate any case to the TEO Attorney or Healthcare CPA; cannot give legal advice or sign a financial representation",
    "quality_metrics": [
     "Review turnaround time",
     "Rework rate on analyst-approved findings (<6% target)"
    ],
    "workload_risks": [
     "Portfolio-review volume spikes across many facilities at once"
    ]
   },
   {
    "role": "TEO Attorney (independently engaged)",
    "responsibilities": [
     "Review and sign the §501(r) compliance determination on every Compliance File",
     "Lead the correction-and-disclosure strategy on every Remediation & Defense matter",
     "Quarterly attorney-reviewed requirement-corpus red-team audit"
    ],
    "contexts": [
     "Sign-Off & Escalation",
     "Requirement Corpus"
    ],
    "decisions_owned": [
     "Final compliance determination on novel/high-risk fact patterns",
     "Requirement-corpus entry approval for a new state overlay"
    ],
    "ai_support": "AI-prepared Requirement Diff and citation trail shortens attorney review time; the sign-off itself never automates",
    "approval_authority": "Required sign-off on every compliance determination and correction-and-disclosure strategy",
    "escalation_authority": "Final authority on any litigation-adjacent or UPL boundary question",
    "quality_metrics": [
     "Attorney turnaround time",
     "Zero unauthorized-practice-of-law incidents"
    ],
    "workload_risks": [
     "Attorney bottleneck as System Portfolio volume grows"
    ]
   },
   {
    "role": "Healthcare CPA (independently engaged)",
    "responsibilities": [
     "Review and sign the AGB Workpaper on every Compliance File",
     "Review and sign the Schedule H representation",
     "Flag AGB or reserve-adequacy-style discrepancies to the Compliance Analyst"
    ],
    "contexts": [
     "Sign-Off & Escalation",
     "Requirement Compliance"
    ],
    "decisions_owned": [
     "AGB Workpaper sign-off",
     "Schedule H representation sign-off"
    ],
    "ai_support": "AI-computed AGB Workpaper and tie-out flags shorten CPA review time; the sign-off itself never automates",
    "approval_authority": "Required sign-off on every AGB Workpaper and Schedule H representation",
    "escalation_authority": "Can require corrected remittance data before signing",
    "quality_metrics": [
     "CPA turnaround time",
     "Zero material AGB miscalculation incidents"
    ],
    "workload_risks": [
     "CPA bottleneck during annual AGB-recalculation season"
    ]
   },
   {
    "role": "Founder / Compliance Lead",
    "responsibilities": [
     "Own intake, sales, and the Compliance Analyst role at launch",
     "Contract and coordinate the TEO Attorney and Healthcare CPA",
     "Own the pilot-cohort go/no-go decision at each checkpoint"
    ],
    "contexts": [
     "Facility Intake",
     "Sign-Off & Escalation",
     "Portfolio Compliance"
    ],
    "decisions_owned": [
     "Pilot-cohort admission",
     "Pricing confirmation per engagement"
    ],
    "ai_support": "Full visibility into every workflow stage via the dashboard",
    "approval_authority": "Business-level go/no-go only; never substitutes for TEO Attorney or Healthcare CPA sign-off",
    "escalation_authority": "Escalates to the TEO Attorney or Healthcare CPA on any compliance question",
    "quality_metrics": [
     "Pilot conversion rate",
     "COGS per engagement"
    ],
    "workload_risks": [
     "Single point of failure at launch until a second Compliance Analyst is hired"
    ]
   }
  ],
  "human_review_checkpoints": [
   "Every determination below the confidence threshold",
   "Every Compliance File before delivery (100%, no exceptions)",
   "Every TEO Attorney Determination and every escalated determination (attorney sign-off)",
   "Final System Portfolio Review before delivery to a retainer facility"
  ],
  "escalation_matrix": [
   "Confidence below threshold, a novel correction-and-disclosure fact pattern, or an active IRS examination -> automatic routing to the TEO Attorney",
   "An AGB tie-out discrepancy or a reserve-adequacy-style red flag -> automatic routing to the Healthcare CPA",
   "A dispute or fact pattern trending toward litigation -> documented Compliance File handed to the facility's own counsel; FacilityFile steps back from legal advocacy"
  ],
  "manual_override_rules": [
   "A Compliance Analyst may manually reclassify a request's purpose category when new facts change the correct Requirement Corpus citation",
   "A Compliance Analyst may manually route a below-threshold case for a second analyst opinion before attorney escalation"
  ],
  "separation_of_duties": [
   "The analyst who drafts an escalation reason is never the same person who signs the resulting TEO Attorney Determination (that is always the attorney bench)"
  ],
  "quality_control_workflow": [
   "Classification gate -> delivery gate -> certification gate (the three permanent human-in-the-loop gates)",
   "5-10% random re-verification of standard-tier determinations",
   "Monthly seeded-error red-team runs against known failure patterns"
  ],
  "data_objects": [
   {
    "name": "ComplianceEngagement",
    "meaning": "One proposed 501(r) expenditure submitted for review.",
    "owner_context": "Intake",
    "writers": [
     "Extraction Agent",
     "Hospital Facility"
    ],
    "readers": [
     "Determination",
     "Review & Escalation",
     "Portfolio Compliance"
    ],
    "source_of_truth": "Intake context",
    "retention": "Engagement-letter-defined retention period",
    "privacy": "Sensitive; facility benefit-status heightened",
    "audit": "Every state transition timestamped in the append-only audit log"
   },
   {
    "name": "ComplianceFile",
    "meaning": "One dated, cited compliance verdict for a Compliance Engagement.",
    "owner_context": "Determination",
    "writers": [
     "Classification Agent",
     "Drafting Agent",
     "Compliance Analyst"
    ],
    "readers": [
     "Review & Escalation",
     "Portfolio Compliance",
     "Facility (via delivery)"
    ],
    "source_of_truth": "Determination context",
    "retention": "Engagement-letter-defined retention period",
    "privacy": "Sensitive financial + benefit-status data",
    "audit": "Hash-chained snapshot per delivered memo"
   },
   {
    "name": "RuleMatrixEntry",
    "meaning": "One versioned rule (26 CFR 1.501(r) provision, state IRS-supplement rule, or CHNA QDE guidance) with a citation anchor.",
    "owner_context": "Requirement Corpus",
    "writers": [
     "TEO Attorney"
    ],
    "readers": [
     "Determination",
     "Portfolio Compliance"
    ],
    "source_of_truth": "Requirement Corpus context",
    "retention": "Indefinite, versioned",
    "privacy": "Not sensitive — regulatory reference data",
    "audit": "Change log with source citation for every update"
   }
  ],
  "read_models": [
   "Exception Queue view (per analyst, severity-tiered)",
   "Attorney-bench queue (per attorney, escalation-reason tagged)",
   "Portfolio dashboard (per facility, all active retainer determinations)",
   "Determinations-delivered / SLA-hit scorecard (per facility and aggregate)"
  ],
  "reporting_models": [
   "System Portfolio Review summary",
   "Annual Requirement Corpus currency report"
  ],
  "data_duplication_notes": [
   "Request data is normalized once at Intake and never re-parsed downstream — Determination, Review & Escalation, and Portfolio Compliance all read the same canonical record",
   "Requirement Corpus citations are written once and referenced (not copied) by Determination and Portfolio Compliance"
  ],
  "data_retention": [
   "Facility benefit-status and compliance engagement data retained for the engagement-letter-defined retention period",
   "Evidence List retained for the same period, extended under an active legal hold",
   "Data deleted per the offboarding SOP on engagement termination unless a legal hold applies"
  ],
  "data_quality_risks": [
   "Inconsistent submission formats across different facility case-management tools",
   "Facility benefit-status data going stale between the submission date and the review date",
   "A prior CHNA and policy record on file becoming outdated after an amendment the facility didn't flag"
  ],
  "use_cases": [
   {
    "name": "Standard determination cycle",
    "actor": "Compliance Analyst",
    "context": "Intake / Determination / Review & Escalation",
    "goal": "A complete Compliance Engagement reviewed and delivered within the 1-business-day SLA",
    "preconditions": [
     "Facility onboarded with a signed engagement letter",
     "Requirement Corpus covers the facility's state"
    ],
    "main_flow": [
     "Facility submits the request",
     "Deterministic Rule Checks and classification run",
     "Analyst reviews and approves the draft",
     "Compliance File delivered"
    ],
    "alternative_flows": [
     "A below-threshold classification routes to the Exception Queue before delivery"
    ],
    "business_rules": [
     "No memo is delivered without an analyst-approved sign-off"
    ],
    "ai_role": "Drafts the classification, Requirement Diff, and memo narrative",
    "human_role": "Analyst reviews the draft and approves delivery",
    "commands": [
     "ClassifyAndDraftDetermination",
     "DeliverComplianceFile"
    ],
    "events": [
     "determination.drafted"
    ],
    "aggregates": [
     "ComplianceFileAggregate"
    ],
    "success": "Memo delivered on time with a fully cited verdict",
    "failure_handling": "A missed SLA triggers a root-cause review of the review-queue capacity",
    "audit": "Full cycle logged in the append-only evidence list"
   },
   {
    "name": "Escalated / TEO Attorney Determination cycle",
    "actor": "TEO Attorney",
    "context": "Review & Escalation",
    "goal": "A novel, high-value, or Certified-Opinion-requested determination reviewed and signed by a licensed attorney",
    "preconditions": [
     "Escalation criteria triggered or TEO Attorney Determination requested"
    ],
    "main_flow": [
     "Escalation-Triage Agent routes the case with a logged reason",
     "Attorney reviews the AI-prepared draft and citation trail",
     "Attorney signs or requests more facts",
     "Compliance File delivered with the attorney's signature"
    ],
    "alternative_flows": [
     "Attorney requests additional facts before signing, extending the SLA with facility notice"
    ],
    "business_rules": [
     "No TEO Attorney Determination is delivered without an attorney signature"
    ],
    "ai_role": "Prepares the draft memo and citation trail to shorten attorney review time",
    "human_role": "Attorney makes the final legal determination and signs",
    "commands": [
     "EscalateToAttorneyBench",
     "SignDetermination"
    ],
    "events": [
     "RequestEscalated",
     "DeterminationSigned"
    ],
    "aggregates": [
     "EscalationCaseAggregate"
    ],
    "success": "TEO Attorney Determination delivered with a complete signature manifest",
    "failure_handling": "An attorney-bench bottleneck triggers a review of bench capacity and turnaround-time KPIs",
    "audit": "Attorney name, bar number, and signed memo retained"
   }
  ],
  "invariants": [
   {
    "invariant": "A Compliance File cannot be delivered without at least one Compliance Analyst sign-off",
    "context": "Review & Escalation",
    "aggregate": "EscalationCaseAggregate",
    "why": "Prevents an unreviewed or wrong determination from reaching a facility and affecting a real compliance engagement decision",
    "enforcement": "Application-service-level guard; no delivery command executes without a recorded analyst approval event"
   },
   {
    "invariant": "A TEO Attorney Determination cannot be delivered without a licensed attorney's signature",
    "context": "Review & Escalation",
    "aggregate": "EscalationCaseAggregate",
    "why": "The TEO Attorney Determination tier is a genuine licensed-attorney work product by definition",
    "enforcement": "Delivery command requires a recorded attorney signature event for any case flagged certified"
   },
   {
    "invariant": "A Deterministic Rule Check result is never overridden by AI classification",
    "context": "Determination",
    "aggregate": "ComplianceFileAggregate",
    "why": "The highest-consequence thresholds (excise-tax threshold, AGB formula, CHNA cap) must be deterministic and auditable, never a model inference",
    "enforcement": "Deterministic code runs before and independently of the classification model; the model cannot alter a Deterministic Rule Check output"
   },
   {
    "invariant": "No facility's or family member's IRS `my Social Security` or CHNA program portal credential is ever collected, stored, or used by FacilityFile",
    "context": "Intake",
    "aggregate": "ComplianceEngagementAggregate",
    "why": "FacilityFile is never the facility's representative and must not create an unauthorized-access or credential-custody risk",
    "enforcement": "Schema-level rejection of any credential-shaped field; code-level guard blocks the workflow"
   },
   {
    "invariant": "A ComplianceEngagement cannot enter the review queue until intake completeness is satisfied or a named exception is logged",
    "context": "Intake",
    "aggregate": "ComplianceEngagementAggregate",
    "why": "Prevents wasted analyst time on requests missing the facts needed for a defensible determination",
    "enforcement": "State-machine guard on the ComplianceEngagement lifecycle"
   }
  ],
  "architecture": {
   "style": "Modular monolith, single production region",
   "why": "A 5-8-account pilot cohort does not justify microservices; module boundaries mirror the bounded contexts so a future split is cheap.",
   "rejected_alternatives": [
    "Microservices from day one (premature operational overhead for a pilot cohort)",
    "No-code workflow tool (can't enforce the deterministic Deterministic Rule Check and citation invariants)"
   ],
   "backend_modules": [
    "intake",
    "determination",
    "review-escalation",
    "portfolio-compliance",
    "rule-matrix"
   ],
   "frontend_modules": [
    "analyst exception-queue console",
    "internal reporting console (no facility-facing portal at launch)"
   ],
   "api_boundaries": [
    "Internal-only APIs between backend modules",
    "No public API surface at launch (email/upload-link intake and email/document delivery only)"
   ],
   "database_strategy": "Single Postgres instance, per-facility row-level partitioning; no per-facility dedicated infrastructure at pilot scale.",
   "event_bus": "In-process domain event dispatch at pilot scale; a lightweight external event bus is deferred until multi-analyst concurrency requires it.",
   "queue": "Background job queue for extraction and classification batches; per-tenant concurrency caps.",
   "workflow_engine": "Deterministic rules engine (code) for Deterministic Rule Checks and completeness gates; no general-purpose workflow engine needed at this scale.",
   "ai_orchestration": "Frontier LLM API called from typed service functions per agent (Extraction, Classification, Drafting, Escalation-Triage, Portfolio Drift-Detection); no autonomous multi-step agent loops.",
   "rag_layer": "Retrieval over the versioned Requirement Corpus, citation-linked, not free-form.",
   "file_storage": "Encrypted object storage, per-facility access-controlled buckets, for compliance engagement-request documents and Compliance Files.",
   "authn_authz": "SSO with MFA for internal staff; role-based capability checks enforced server-side (Compliance Analyst, Attorney bench, Founder).",
   "admin_dashboard": "Internal-only; no facility-facing admin surface at launch.",
   "client_portal": "None at launch — the facility never operates software; deliverables are documents by email.",
   "operator_dashboard": "Compliance Analyst exception-queue console with severity tiers and SLA timers.",
   "observability": "Structured logs, RED metrics per workflow, model-call cost/latency spans.",
   "audit_logging": "Append-only, hash-chained snapshots per Compliance File; every request state observed is timestamped.",
   "deployment": "Single-region, multi-AZ production; preview environment per PR."
  },
  "module_structure": {
   "tree": "src/{intake,determination,review-escalation,portfolio-compliance,rule-matrix}/{domain,application,infra}",
   "modules": [
    {
     "name": "intake",
     "purpose": "Compliance Engagement request normalization and completeness checking",
     "owned_domain": [
      "ComplianceEngagement"
     ],
     "application_services": [
      "SubmitComplianceEngagement",
      "NormalizeRequestData"
     ],
     "infra_adapters": [
      "Email/upload intake handler",
      "Object storage adapter",
      "LLM extraction client"
     ],
     "public_interfaces": [
      "RequestDataNormalized event"
     ],
     "forbidden_deps": [
      "Must not depend on review-escalation or portfolio-compliance internals"
     ]
    },
    {
     "name": "determination",
     "purpose": "Deterministic Rule Checks, classification, and memo drafting",
     "owned_domain": [
      "ComplianceFile (draft)"
     ],
     "application_services": [
      "RunBrightLineChecks",
      "ClassifyAndDraftDetermination"
     ],
     "infra_adapters": [
      "LLM classification client",
      "Requirement Corpus reader"
     ],
     "public_interfaces": [
      "DeterminationDrafted event"
     ],
     "forbidden_deps": [
      "Must not write to intake's tables"
     ]
    },
    {
     "name": "review-escalation",
     "purpose": "Analyst review, attorney escalation, and delivery",
     "owned_domain": [
      "EscalationCase"
     ],
     "application_services": [
      "EscalateToAttorneyBench",
      "SignDetermination",
      "DeliverComplianceFile"
     ],
     "infra_adapters": [
      "Email send adapter",
      "E-signature adapter"
     ],
     "public_interfaces": [
      "DeterminationDelivered event"
     ],
     "forbidden_deps": [
      "Must not perform classification logic"
     ]
    },
    {
     "name": "portfolio-compliance",
     "purpose": "Retainer tracking, quarterly review assembly, drift detection",
     "owned_domain": [
      "PortfolioReview"
     ],
     "application_services": [
      "RunQuarterlyPortfolioReview"
     ],
     "infra_adapters": [
      "Report template renderer",
      "Object storage adapter"
     ],
     "public_interfaces": [
      "PortfolioDriftDetected event"
     ],
     "forbidden_deps": [
      "Must not draft individual determinations directly"
     ]
    },
    {
     "name": "rule-matrix",
     "purpose": "Versioned per-jurisdiction rule sets with citation anchors",
     "owned_domain": [
      "RuleMatrixEntry"
     ],
     "application_services": [
      "UpdateRuleMatrix"
     ],
     "infra_adapters": [
      "Regulatory-change diff detector"
     ],
     "public_interfaces": [
      "RuleMatrixVersionPublished event"
     ],
     "forbidden_deps": [
      "Must not depend on any facility-specific data"
     ]
    }
   ],
   "dependency_rules": [
    "Downstream contexts consume upstream domain events; no direct cross-module table access",
    "rule-matrix has no dependency on any other module"
   ]
  },
  "security_governance": {
   "controls": [
    {
     "risk": "A wrong or unreviewed determination reaches a facility",
     "context": "Determination",
     "impact": "high",
     "control": "Confidence-scored classification + mandatory analyst confirmation below threshold + 5-10% sampled re-verification",
     "audit": "Classification rationale + confidence score logged per request"
    },
    {
     "risk": "Cross-facility data leak, including facility benefit-status records",
     "context": "Intake / Determination",
     "impact": "severe",
     "control": "Row-level auth + per-facility retrieval partitioning",
     "audit": "Access logs reviewed weekly"
    },
    {
     "risk": "A facility/family credential is collected in violation of the documented prohibition",
     "context": "Intake",
     "impact": "severe",
     "control": "Schema-level rejection of any credential-shaped field; code-level guard",
     "audit": "Automated schema-validation test in CI"
    }
   ],
   "ai_governance": [
    "Every AI-drafted output is confidence-scored and cited",
    "No dollar figure is ever LLM-computed",
    "Analyst approval required before any delivery"
   ],
   "prompt_injection_defense": [
    "Uploaded compliance-engagement-request/policy-document content treated as untrusted data, never as instructions",
    "Output schema validation on every agent response before it reaches a human queue"
   ],
   "sensitive_data_handling": [
    "Facility benefit-status and financial data classified sensitive with least-privilege access",
    "Per-facility segregation with no shared indices across facilities",
    "Deletion SLA enforced on offboarding"
   ],
   "access_control_matrix": [
    {
     "role": "Compliance Analyst",
     "context": "Determination / Review & Escalation / Portfolio Compliance",
     "capabilities": [
      "Approve classifications below threshold",
      "Release Compliance Files",
      "Sign off on System Portfolio Reviews"
     ]
    },
    {
     "role": "TEO Attorney",
     "context": "Review & Escalation / Requirement Corpus",
     "capabilities": [
      "Sign escalated and TEO Attorney Determination determinations",
      "Approve new Requirement Corpus jurisdiction entries"
     ]
    },
    {
     "role": "Founder",
     "context": "Requirement Corpus / Referral & Outreach",
     "capabilities": [
      "Admit pilot facilities",
      "Approve state-expansion sequencing"
     ]
    }
   ],
   "audit_log_requirements": [
    "Every request state observed, every determination drafted, every rule applied is timestamped per request",
    "Hash-chained snapshots for every delivered Compliance File"
   ]
  },
  "observability": {
   "metrics": [
    {
     "metric": "Auto-classification accuracy",
     "type": "gauge",
     "context": "Determination",
     "why": "Tracks how much of the classification workload runs correctly without analyst correction",
     "target": "improving toward 85%+ by day 90",
     "alert_threshold": "<50% sustained for 2 weeks"
    },
    {
     "metric": "Benefit-suspension incidents traced to a delivered determination",
     "type": "counter",
     "context": "Review & Escalation",
     "why": "The zero-tolerance quality target",
     "target": "0",
     "alert_threshold": ">0 triggers immediate root-cause review"
    },
    {
     "metric": "Determination cycle time",
     "type": "histogram",
     "context": "Review & Escalation",
     "why": "SLA is 1 business day standard / 4 hours rush",
     "target": "<=1 business day standard",
     "alert_threshold": ">1.5 business days"
    }
   ],
   "dashboards": [
    "Analyst exception-queue dashboard (severity-tiered, SLA timers)",
    "Aggregate determinations-delivered / SLA-hit scorecard"
   ],
   "audit_reports": [
    "Monthly audit-trail completeness report per facility"
   ],
   "quality_review_reports": [
    "Monthly seeded-error red-team result summary"
   ],
   "ai_evaluation_reports": [
    "Quarterly gold-standard regression report"
   ],
   "client_outcome_reports": [
    "Compliance File per request",
    "System Portfolio Review per retainer facility"
   ]
  },
  "testing_strategy": {
   "tests": [
    {
     "type": "unit",
     "validates": "Deterministic Rule Check math (excise-tax threshold, AGB formula, CHNA cap)",
     "context": "Determination",
     "example": "A $500 direct rent payment computes the correct AGB-percentage reduction"
    },
    {
     "type": "component",
     "validates": "Exception-queue routing on below-threshold classifications",
     "context": "Determination",
     "example": "A 60%-confidence classification routes to attorney escalation, never auto-delivers"
    },
    {
     "type": "e2e",
     "validates": "Full intake -> classification -> analyst sign-off -> delivery path",
     "context": "cross-context",
     "example": "A seeded sample request produces a correctly delivered Compliance File end-to-end"
    }
   ],
   "critical_domain_rules": [
    "AGB resource-limit Deterministic Rule Check",
    "AGB-percentage formula",
    "Low-confidence attorney-escalation rule"
   ],
   "ai_eval_dataset": [
    "Gold-standard adjudicated determination examples",
    "Seeded error requests for red-team runs (ambiguous AGB cases, mixed 501(r) fact patterns)"
   ],
   "regression_plan": "Every Requirement Corpus version bump re-runs the full gold-standard regression suite before the new rule set goes live for any facility.",
   "contract_testing_plan": "Contract tests validate the canonical compliance engagement-request schema against every supported submission format sampled from the pilot cohort.",
   "manual_qa_checklist": [
    "Analyst spot-checks 5-10% of standard-tier determinations each cycle",
    "Monthly red-team seeded-error run reviewed by the founder",
    "Quarterly review reviewed against the completeness checklist before delivery"
   ]
  },
  "mvp_roadmap": [
   {
    "phase": "MVP — Compliance Engagement Determination Cycle",
    "goal": "Prove the classify-review-deliver loop manually-assisted for the first 3-5 pilot facilities",
    "features": [
     "Facility Readiness Scan intake + readout",
     "Standard determination delivery",
     "Exception Queue escalation"
    ],
    "contexts": [
     "Intake",
     "Determination",
     "Review & Escalation"
    ],
    "ai_needs": [
     "Extraction Agent",
     "Classification Agent",
     "Drafting Agent"
    ],
    "human_workflows": [
     "Founder reviews every exception and every delivery personally for the first 5 pilots"
    ],
    "data_needs": [
     "Federal 26 CFR 1.501(r) + founder's home-state Requirement Corpus v0"
    ],
    "integrations": [
     "Email/upload intake, secure email delivery"
    ],
    "risks": [
     "Manual founder bottleneck at volume"
    ],
    "exit_criteria": [
     "5 pilot facilities with at least one completed determination each, zero SLA misses"
    ]
   }
  ],
  "scaling_roadmap": [
   {
    "stage": "3-5 -> 5-8 pilot accounts",
    "trigger": "5-pilot hardening checkpoint passed (intake spec, evidence requirements, QA checklists standardized)",
    "architecture_change": "Introduce AI drafting layer against a growing adjudicated-example library; certify a second Compliance Analyst",
    "operational_change": "Exception-queue tiers and escalation-criteria checklists formalized",
    "risk": "Per-facility snowflake logic that can't be ruled is a stop-the-line signal"
   },
   {
    "stage": "8 -> 10+ accounts (multi-state wave)",
    "trigger": "Gross margin trending toward the 50-55% target and zero benefit-suspension incidents in the trailing quarter",
    "architecture_change": "Additional state Requirement Corpus entries codified and attorney-reviewed",
    "operational_change": "Pause new onboarding at the 20-pilot checkpoint until cost-per-determination, rework rate, escalation rate, and cycle time are measured",
    "risk": "New-state IRS-supplement rule volatility during a program's first year of coverage"
   }
  ],
  "risk_register": [
   {
    "risk": "A state charity-care overlay change breaks a codified requirement path mid-cycle",
    "likelihood": "high",
    "impact": "medium",
    "signal": "A tracked regulatory source change is detected outside a scheduled review window",
    "mitigation": "Requirement corpus versioned per jurisdiction with change-monitoring",
    "owner": "product",
    "context": "Requirement Corpus"
   },
   {
    "risk": "TEO Attorney / Healthcare CPA bottleneck as System Portfolio volume grows",
    "likelihood": "medium",
    "impact": "medium",
    "signal": "Sign-off turnaround time exceeds the KPI target",
    "mitigation": "Build a bench of 2-3 contracted TEO attorneys and healthcare CPAs across relevant jurisdictions before scaling past the pilot cohort",
    "owner": "owner",
    "context": "Sign-Off & Escalation"
   },
   {
    "risk": "Fuzzy classification error routes a requirement to the wrong finding",
    "likelihood": "low",
    "impact": "high",
    "signal": "Sampled re-verification finds a mismatch",
    "mitigation": "Confidence thresholds + mandatory analyst confirmation below threshold + deterministic requirement gates",
    "owner": "engineering",
    "context": "Requirement Compliance"
   }
  ],
  "adrs": [
   {
    "id": "ADR-001",
    "decision": "Launch as a single-region modular monolith, not microservices",
    "status": "accepted",
    "context": "A 5-8-account pilot cap does not justify microservice operational overhead",
    "options": [
     "Modular monolith",
     "Microservices",
     "No-code workflow tool"
    ],
    "chosen": "Modular monolith",
    "business_reason": "Fastest path to the first 3-5 pilot determinations without a platform team",
    "technical_reason": "Module boundaries mirror bounded contexts, keeping a future split cheap",
    "tradeoffs": [
     "[PLACEHOLDER] owner to complete"
    ],
    "risks": [
     "[PLACEHOLDER] owner to complete"
    ],
    "revisit_trigger": "Sustained load beyond the analyst-throughput target",
    "why": "Matches the actual pilot scale",
    "consequences": "Single deploy unit, simpler ops, requires discipline on module boundaries",
    "reversal": "Extract a module to a service if its load profile diverges sharply",
    "revisit_when": "Post-20-pilot pause-and-measure checkpoint"
   },
   {
    "id": "ADR-002",
    "decision": "No facility-facing portal at launch; delivery is email/document only",
    "status": "accepted",
    "context": "The blueprint's sales thesis is that the facility never operates software",
    "options": [
     "Build a facility-facing dashboard",
     "Email/document delivery only",
     "White-labeled third-party portal"
    ],
    "chosen": "Email/document delivery only",
    "business_reason": "Matches the 'we sell a determination, not a dashboard' positioning",
    "technical_reason": "Removes an entire authn/authz surface at pilot scale",
    "tradeoffs": "No self-serve visibility for the facility between determinations",
    "risks": "A facility used to a dashboard may perceive the service as less real-time",
    "revisit_trigger": "Multiple pilot facilities request live status visibility",
    "why": "Keeps the MVP thin and evidence-linked",
    "consequences": "Delivered memos and readout calls carry the full trust burden",
    "reversal": "Add a lightweight read-only status view if demand is proven",
    "revisit_when": "After the 10-pilot hardening checkpoint"
   }
  ],
  "self_audit": {
   "scores": [
    {
     "category": "Domain clarity",
     "score": 5,
     "weakness": "None material",
     "improvement": "Keep the Requirement Corpus citation discipline as new states are added"
    },
    {
     "category": "Human-chokepoint discipline",
     "score": 5,
     "weakness": "None material",
     "improvement": "Continue dual review on high-value TEO Attorney Determinations as volume grows"
    },
    {
     "category": "Regulatory-boundary clarity",
     "score": 4,
     "weakness": "Unauthorized-practice-of-law boundary requires counsel review before the first paid engagement",
     "improvement": "Complete counsel review before onboarding pilot 1"
    }
   ],
   "weakest_parts": [
    "TEO Attorney Determination pricing economics are Unverified until real attorney-time data exists",
    "Total national FAP count is Unverified — sized only directionally"
   ],
   "biggest_assumptions": [
    "Free-diagnostic-to-paid conversion reaches a viable rate among warm nonprofit hospitals",
    "A 1-business-day determination can run from facility-supplied facts alone without a live IRS data integration"
   ],
   "highest_risk_decisions": [
    "Offering the TEO Attorney Determination at a flat $350 fee before real attorney-time data validates the economics",
    "Onboarding a facility in a new state before that state's IRS-supplement rules are fully attorney-reviewed"
   ],
   "needs_domain_expert": [
    "[PLACEHOLDER] owner to complete"
   ],
   "needs_legal": [
    "[PLACEHOLDER] owner to complete"
   ],
   "needs_prototype": [
    "[PLACEHOLDER] owner to complete"
   ],
   "validate_before_prod": [
    "[PLACEHOLDER] owner to complete"
   ]
  },
  "final_recommendations": [
   "Launch the Facility Compliance Audit pilot immediately: codify 26 CFR 1.501(r) plus the two or three highest-exposure states into the requirement corpus, ship the free Facility Readiness Scan, and recruit 5 founding facility accounts",
   "Hold multi-state overlay expansion as the timed second act once the initial state library and pilot cap are proven",
   "Do not build a facility-facing portal or software product beyond the internal engine until the 10-pilot checkpoint proves margin",
   "Keep the Compliance Analyst approval gate permanent on every delivered Compliance File regardless of automation maturity",
   "Treat Remediation & Defense as a TEO-Attorney-gated revenue line with pricing validated against real attorney and CPA time, never assumed permanent at the initial anchor price"
  ],
  "extensions": {
   "service_business_reality_check": {
    "is_service_business": true,
    "paid_outcome_clear": true,
    "workflow_present": true,
    "ai_native_fit_score": 4.5,
    "red_flags": []
   },
   "ai_native_fit": {
    "score": 4.5,
    "why": "Mechanical, rule-driven workflow (request classification, Deterministic Rule Check application, memo drafting) ideally suited to AI with a clean, permanent human chokepoint on every delivered determination.",
    "disqualifiers": []
   },
   "domain_evidence_register": [
    {
     "claim": "hospital facilities totaled 213,855 nationally as of Q2 2025, up 18.3% YoY from 180,748 (Q2 2024)",
     "evidence_type": "industry association data",
     "source": "NAST Q2 2025 National CHNA Data, via PlanSponsor",
     "strength": "high",
     "gaps": "None — re-confirmed live during this build"
    },
    {
     "claim": "AGB's $50,000 individual countable-excise-tax threshold is unchanged for decades",
     "evidence_type": "primary government source",
     "source": "IRS 26 CFR 1.501(r)",
     "strength": "high",
     "gaps": "A pending bipartisan bill (H.R.2540/S.1234) proposes raising it — not yet law as of this build"
    }
   ],
   "assumption_register": [
    {
     "assumption": "Professional facilities will pay a per-request fee over continuing to decide on memory or a general chatbot",
     "impact_if_wrong": "severe",
     "how_to_validate": "First 5-8 pilot facilities' free-diagnostic-to-paid conversion",
     "blocking": true
    },
    {
     "assumption": "A 1-business-day determination can run from facility-supplied facts alone without a live IRS data integration",
     "impact_if_wrong": "high",
     "how_to_validate": "First 10-15 completed determinations, manually-assisted",
     "blocking": false
    }
   ],
   "language_conflict_map": [
    {
     "term": "account",
     "meaning_a": "A facility's hospital facility (the state program's object)",
     "context_a": "CHNA program terminology",
     "meaning_b": "A FacilityFile client relationship (a 'facility account')",
     "context_b": "Internal sales/ops usage",
     "resolution": "Always qualify: 'hospital facility' for the program object; 'facility engagement' for the client relationship — never bare 'account' in client-facing copy"
    }
   ],
   "build_buy_integrate": [
    {
     "subdomain": "Determination",
     "decision": "build",
     "reason": "Core paid outcome; no vendor sells this per-transaction determination service"
    },
    {
     "subdomain": "Referral & Outreach",
     "decision": "buy",
     "reason": "Lightweight CRM is not differentiating"
    }
   ],
   "core_protection_strategy": [
    "[PLACEHOLDER] owner to complete"
   ],
   "boundary_stress_tests": [
    {
     "scenario": "True Link Financial or a similar fintech ships a documented, per-transaction determination product",
     "contexts_touched": [
      "Determination",
      "Review & Escalation"
     ],
     "breaks_if": "FacilityFile were positioned as a card/tool rather than an operated, attorney-backed outcome",
     "verdict": "Holds — the facility still needs a named analyst and licensed attorney standing behind the determination, not just a report screen"
    }
   ],
   "unresolved_ownership": [
    {
     "concept": "Who owns a facility-level 'benefit-status change' event that affects multiple pending requests at once",
     "candidates": [
      "Determination (per-request)",
      "a new FacilityStatusChange aggregate"
     ],
     "recommendation": "Model a FacilityStatusChange as a future aggregate once pilot volume shows status-change events affecting multiple pending requests are common"
    }
   ],
   "published_language_contracts": [
    {
     "producer": "Requirement Corpus",
     "consumer": "Determination, Portfolio Compliance",
     "contract": "Versioned RuleMatrixEntry schema with citation anchors",
     "versioning": "Semantic version bump on every regulatory-source diff"
    }
   ],
   "shared_kernel_warnings": [
    "Requirement Corpus is a shared kernel across every facility on a given jurisdiction — a bad rule-entry edit affects every client simultaneously; changes require the same review rigor as a production migration"
   ],
   "aggregate_stress_tests": [
    {
     "aggregate": "ComplianceFileAggregate",
     "scenario": "A facility's compliance status changes mid-review (e.g., a IRS redetermination completes while a request is pending)",
     "invariant_at_risk": "The memo's Requirement Diff reflects the facility's status at classification time, not at delivery time",
     "verdict": "Holds if the status-change date is captured and the memo is re-classified before delivery; flagged as a status-change exception for analyst review either way"
    }
   ],
   "agent_stress_tests": [
    {
     "agent": "Classification Agent",
     "scenario": "A compliance engagement plausibly qualifies under either the FAP AGB rules or the CHNA QDE rules depending on account type",
     "failure_mode": "Could propose a plausible but wrong rule-set classification if account type isn't explicit",
     "guardrail": "Account-type field is required at intake; ambiguous or missing account type forces analyst confirmation before classification",
     "verdict": "Holds with the guardrail; would fail without the required account-type field"
    }
   ],
   "regulated_domain_handling": [
    {
     "regime": "Unauthorized practice of law",
     "applies_because": "Standard determinations are compliance research, but the boundary with individualized legal advice must be actively managed",
     "controls": [
      "Engagement-letter scoping positioning standard determinations as research delivered to the facility customer of record",
      "Escalation criteria route any borderline legal-judgment case to the attorney bench automatically"
     ],
     "evidence_required": [
      "[PLACEHOLDER] owner to complete"
     ]
    },
    {
     "regime": "Facility data privacy (financial + benefit-status)",
     "applies_because": "FacilityFile processes facility financial and means-tested-benefit-status data under facility authorization",
     "controls": [
      "Signed engagement letter with confidentiality and deletion terms",
      "No facility/family credential ever collected"
     ],
     "evidence_required": "Signed engagement letter per facility before any request is worked"
    }
   ],
   "unit_economics": {
    "price_model": "Per-Compliance Engagement-Request flat fee + Annual Compliance File subscription + TEO Attorney Determination flat fee",
    "unit_of_value": "one delivered Compliance File",
    "gross_margin_pct": 53,
    "cost_drivers": [
     "Model inference (classification, drafting): $1-2/determination at day-90 maturity",
     "Compliance Analyst review time (~10-20 min @ loaded rate): $8-10/determination",
     "QA sampling amortized + delivery tooling: $1.50-2.50/determination"
    ],
    "breakeven_note": "COGS ~$20-24/standard determination at day 90 vs. a $52.50 blended standard/rush price — roughly 53-55% gross margin target, consistent with the blueprint's explicitly stated 50-55% figure (see financial-model.csv header notes for the reconciliation against the blueprint's separately itemized, lower COGS line-items)."
   },
   "margin_leakage_map": [
    {
     "leakage": "Per-facility snowflake case-management integration requests",
     "cause": "Pilot facilities requesting one-off bespoke reporting outside the standard Compliance File template",
     "impact": "Analyst minutes balloon past the day-90 target, eroding gross margin",
     "mitigation": "Product-vs-custom rule enforced from pilot 1; decline or separately price bespoke requests"
    }
   ],
   "slop_findings": [
    {
     "pattern": "Generic 'AI-powered platform' framing",
     "status": "avoided",
     "note": "All copy anchors to specific mechanics (the $50,000 excise-tax threshold, the AGB formula, named 26 CFR 1.501(r) sections) rather than generic AI claims"
    }
   ],
   "drift_checks": [
    {
     "stage": "DNA vs. landing page vs. playbook lexicon",
     "status": "checked",
     "findings": [
      "[PLACEHOLDER] owner to complete"
     ]
    }
   ],
   "gates": [
    {
     "id": "gate-1",
     "title": "Human-chokepoint completeness",
     "passed": true,
     "checks": [
      {
       "name": "Every delivered determination has an analyst-approval invariant",
       "ok": true,
       "evidence": "ddd.invariants entry + Review & Escalation bounded-context invariants"
      },
      {
       "name": "Every TEO Attorney Determination has an attorney-sign-off gate",
       "ok": true,
       "evidence": "ddd.policies 'TEO Attorney Determination attorney sign-off'"
      },
      {
       "name": "No facility/family credential handling anywhere in the workflow",
       "ok": true,
       "evidence": "ddd.invariants 'No facility...credential' + security_governance controls"
      }
     ]
    }
   ],
   "contradiction_scan": [
    {
     "id": "cs-1",
     "severity": "none",
     "message": "No contradiction found between the blueprint's licensing boundary and the DDD security_governance/compliance sections.",
     "refs": [
      "product.security.compliance_targets",
      "ddd.security_governance.controls"
     ]
    }
   ],
   "rubric": {
    "categories": [
     {
      "category": "Domain modeling completeness",
      "score": 5,
      "min": 3,
      "passed": true
     },
     {
      "category": "Human-in-the-loop rigor",
      "score": 5,
      "min": 3,
      "passed": true
     },
     {
      "category": "Regulatory-boundary clarity",
      "score": 4,
      "min": 3,
      "passed": true
     },
     {
      "category": "Evidence traceability",
      "score": 4,
      "min": 3,
      "passed": true
     },
     {
      "category": "Anti-genericness (lexicon specificity)",
      "score": 5,
      "min": 3,
      "passed": true
     }
    ],
    "pass": true,
    "average": 4.6
   },
   "foundry_package": {
    "version": "1.0",
    "checksum": "n/a-generated-locally",
    "counts": {
     "subdomains": 5,
     "bounded_contexts": 5,
     "aggregates": 5,
     "events": 6,
     "commands": 6,
     "policies": 4,
     "ai_agents": 5,
     "invariants": 5,
     "integrations": 4,
     "adrs": 2
    },
    "subset": {
     "subdomains": [
      "Determination",
      "Review & Escalation",
      "Portfolio Compliance",
      "Requirement Corpus",
      "Referral & Outreach"
     ],
     "bounded_contexts": [
      "Intake",
      "Determination",
      "Review & Escalation",
      "Portfolio Compliance",
      "Requirement Corpus"
     ],
     "aggregates": [
      "ComplianceEngagementAggregate",
      "ComplianceFileAggregate",
      "EscalationCaseAggregate",
      "PortfolioReviewAggregate",
      "RuleMatrixVersionAggregate"
     ],
     "events": [
      "ComplianceEngagementSubmitted",
      "DeterminationDrafted",
      "RequestEscalated",
      "DeterminationSigned",
      "DeterminationDelivered",
      "RuleMatrixVersionPublished"
     ],
     "commands": [
      "SubmitComplianceEngagement",
      "RunBrightLineChecks",
      "ClassifyAndDraftDetermination",
      "EscalateToAttorneyBench",
      "SignDetermination",
      "DeliverComplianceFile"
     ],
     "policies": [
      "Deterministic-Rule resource-limit gate",
      "Low-confidence escalation",
      "100%-analyst-review requirement",
      "TEO Attorney Determination attorney sign-off"
     ],
     "ai_agents": [
      "Extraction Agent",
      "Classification Agent",
      "Drafting Agent",
      "Escalation-Triage Agent",
      "Portfolio Drift-Detection Agent"
     ],
     "invariants": [
      "Compliance File analyst sign-off required",
      "TEO Attorney Determination attorney signature required",
      "Deterministic Rule Check never overridden by AI",
      "No facility/family credential handling",
      "Intake completeness required before review"
     ],
     "integrations": [
      "Secure intake portal/email",
      "E-signature tool (attorney sign-off)",
      "Lightweight CRM",
      "OCR/document-extraction tool"
     ],
     "adrs": [
      "ADR-001",
      "ADR-002"
     ]
    }
   }
  }
 },
 "architecture": {
  "slug": "501r-community-benefit-compliance-engine",
  "archetypes": [
   "compliance determination desk",
   "elder & disability-benefits advisory-adjacent service"
  ],
  "archetype_impact": "Drives a request-in / cited-memo-out shape with a permanent human-plus-attorney approval gate before any delivery, rather than a self-serve SaaS shape.",
  "personality": [
   "Quiet, evidence-first, never alarmist",
   "Citation-literal (26 CFR 1.501(r) sections and dollar amounts stated exactly, never vague)",
   "Facility-branded internally — FacilityFile is the facility's own compliance desk, not a family-facing product",
   "Audit-grade precision in every citation"
  ],
  "forces_ranked": [
   {
    "force": "Regulatory/evidence fidelity",
    "why": "Every citation and dollar figure must be deterministic and sourced — a wrong one costs a facility's benefits and the facility's liability position"
   },
   {
    "force": "Human-plus-attorney chokepoint discipline",
    "why": "The business's entire moat rests on the analyst-approval and attorney-sign-off gates holding on every delivery"
   },
   {
    "force": "Time-to-first-pilot",
    "why": "5-8-account pilot cap must be reachable in 90 days without a platform build"
   },
   {
    "force": "Multi-jurisdiction extensibility",
    "why": "Federal 26 CFR 1.501(r) today, state-by-state IRS-supplement rules next — the Requirement Corpus must generalize across jurisdictions cleanly"
   }
  ],
  "tradeoffs": [
   "Single-region modular monolith trades some scalability headroom for speed-to-pilot and lower ops burden",
   "No facility-facing portal at launch trades self-serve visibility for a thinner, faster-to-ship MVP"
  ],
  "quality_scenarios": [
   {
    "attribute": "Correctness",
    "assumption": "A determination is drafted by the Classification Agent",
    "target": "0 benefit-suspension incidents traced to a delivered determination in the trailing quarter"
   },
   {
    "attribute": "Availability",
    "assumption": "A synchronized portfolio-review volume spike across the full pilot cohort",
    "target": "Determination delivery on time (1-business-day SLA) for 100% of standard requests"
   }
  ],
  "options": [
   {
    "style": "Modular monolith",
    "complexity": "low",
    "cost": "low",
    "ops_burden": "low",
    "team_fit": "high",
    "scaling_path": "Extract a module to a service if its load profile diverges",
    "security_impact": "Simpler perimeter, single auth boundary",
    "fits_here": true,
    "fits_when": "Pilot-to-early-scale (up to a few dozen facilities per analyst)",
    "wrong_here": false,
    "recommended": true
   },
   {
    "style": "Microservices",
    "complexity": "high",
    "cost": "high",
    "ops_burden": "high",
    "team_fit": "low at this stage",
    "scaling_path": "N/A yet",
    "security_impact": "More surface area, more inter-service auth",
    "fits_here": false,
    "fits_when": "Post-pilot multi-analyst scale",
    "wrong_here": true,
    "recommended": false
   },
   {
    "style": "No-code workflow tool",
    "complexity": "low",
    "cost": "low",
    "ops_burden": "low",
    "team_fit": "medium",
    "scaling_path": "Would require a rebuild to add deterministic Deterministic Rule Checks and citation invariants",
    "security_impact": "Vendor-dependent data handling",
    "fits_here": false,
    "fits_when": "Never for this business's compliance-grade evidence requirements",
    "wrong_here": true,
    "recommended": false
   }
  ],
  "chosen_style": "Modular monolith, single production region",
  "chosen_rationale": "Matches the actual 5-8-account pilot scale and keeps the deterministic-rules and human-plus-attorney chokepoint invariants enforceable in one codebase.",
  "rejected": [
   {
    "style": "Microservices",
    "why_rejected": "Operational overhead unjustified below a few dozen facilities per analyst"
   },
   {
    "style": "No-code workflow tool",
    "why_rejected": "Can't cleanly enforce Deterministic Rule Check determinism and citation-required invariants"
   }
  ],
  "target": {
   "overview": "Single-region modular monolith with five domain modules (intake, determination, review-escalation, portfolio-compliance, rule-matrix) behind an internal analyst console; no public API or facility-facing portal at launch.",
   "frontend": "Internal analyst exception-queue and reporting console only",
   "backend": "Typed service layer per module, deterministic rules engine for Deterministic Rule Checks and completeness gates",
   "data": "Single Postgres instance, per-facility row-level partitioning",
   "api": "Internal-only; no public API surface at launch",
   "authn_authz": "SSO + MFA for staff; server-side role capability checks",
   "integrations": "Email/upload intake, secure email delivery, encrypted object storage for evidence and memos",
   "background_jobs": "Extraction and classification batch jobs with per-tenant concurrency caps",
   "object_storage": "Encrypted, per-facility access-controlled buckets",
   "notifications": "Analyst-approved email only; no SMS/push at launch",
   "search": "Citation-linked retrieval over the Requirement Corpus, not general full-text search",
   "analytics": "Internal RED metrics + business-event dashboards; no third-party analytics on facility data",
   "ai": "Frontier LLM API called per agent from typed service functions; retrieval-first, citation-linked",
   "observability": "Structured logs, RED metrics, model-call cost/latency spans",
   "deployment": "Single region + multi-AZ production; per-PR preview environments",
   "security": "Row-level auth, per-facility retrieval partitioning, encrypted storage, least-privilege access",
   "dr": "Daily encrypted backups; documented restore runbook tested quarterly"
  },
  "modules": [
   {
    "name": "intake",
    "purpose": "Compliance Engagement request normalization and completeness checking",
    "owned_domain": [
     "ComplianceEngagement"
    ],
    "application_services": [
     "SubmitComplianceEngagement",
     "NormalizeRequestData"
    ],
    "infra_adapters": [
     "Email/upload intake handler",
     "Object storage adapter",
     "LLM extraction client"
    ],
    "public_interfaces": [
     "RequestDataNormalized event"
    ],
    "forbidden_deps": [
     "Must not depend on review-escalation or portfolio-compliance internals"
    ],
    "responsibility": "Own compliance engagement-request intake and normalization",
    "owned_data": [
     "ComplianceEngagement"
    ],
    "events_produced": [
     "RequestDataNormalized"
    ],
    "events_consumed": [],
    "interfaces": [
     "SubmitComplianceEngagement"
    ],
    "depends_on": [],
    "entities": [
     "ComplianceEngagement"
    ],
    "failure_risks": [
     "Malformed submission silently mis-extracted"
    ],
    "scaling": "Scales with intake batch volume; background-job concurrency capped per facility",
    "future_split_trigger": "Extract to a service if extraction volume exceeds single-instance throughput"
   },
   {
    "name": "determination",
    "purpose": "Deterministic Rule Checks, classification, and memo drafting",
    "owned_domain": [
     "ComplianceFile (draft)"
    ],
    "application_services": [
     "RunBrightLineChecks",
     "ClassifyAndDraftDetermination"
    ],
    "infra_adapters": [
     "LLM classification client",
     "Requirement Corpus reader"
    ],
    "public_interfaces": [
     "DeterminationDrafted event"
    ],
    "forbidden_deps": [
     "Must not write to intake's tables"
    ],
    "responsibility": "Own Deterministic Rule Check execution and determination drafting",
    "owned_data": [
     "ComplianceFile"
    ],
    "events_produced": [
     "DeterminationDrafted"
    ],
    "events_consumed": [
     "RequestDataNormalized"
    ],
    "interfaces": [
     "ClassifyAndDraftDetermination"
    ],
    "depends_on": [
     "intake"
    ],
    "entities": [
     "ComplianceFile"
    ],
    "failure_risks": [
     "Misclassification against a stale Requirement Corpus version"
    ],
    "scaling": "Scales with determination-request volume",
    "future_split_trigger": "Extract to a service once multi-analyst concurrency requires independent scaling"
   },
   {
    "name": "review-escalation",
    "purpose": "Analyst review, attorney escalation, and delivery",
    "owned_domain": [
     "EscalationCase"
    ],
    "application_services": [
     "EscalateToAttorneyBench",
     "SignDetermination",
     "DeliverComplianceFile"
    ],
    "infra_adapters": [
     "Email send adapter",
     "E-signature adapter"
    ],
    "public_interfaces": [
     "DeterminationDelivered event"
    ],
    "forbidden_deps": [
     "Must not perform classification logic"
    ],
    "responsibility": "Own analyst review, attorney escalation, and delivery lifecycle",
    "owned_data": [
     "EscalationCase"
    ],
    "events_produced": [
     "DeterminationDelivered"
    ],
    "events_consumed": [
     "DeterminationDrafted"
    ],
    "interfaces": [
     "DeliverComplianceFile"
    ],
    "depends_on": [
     "determination"
    ],
    "entities": [
     "EscalationCase"
    ],
    "failure_risks": [
     "Missed escalation on a genuinely novel case"
    ],
    "scaling": "Scales with active determination/escalation volume",
    "future_split_trigger": "Extract to a service if attorney-bench coordination volume grows past manual-assisted capacity"
   },
   {
    "name": "portfolio-compliance",
    "purpose": "Retainer tracking, quarterly review assembly, drift detection",
    "owned_domain": [
     "PortfolioReview"
    ],
    "application_services": [
     "RunQuarterlyPortfolioReview"
    ],
    "infra_adapters": [
     "Report template renderer",
     "Object storage adapter"
    ],
    "public_interfaces": [
     "PortfolioDriftDetected event"
    ],
    "forbidden_deps": [
     "Must not draft individual determinations directly"
    ],
    "responsibility": "Own quarterly review assembly and drift detection",
    "owned_data": [
     "PortfolioReview"
    ],
    "events_produced": [
     "PortfolioDriftDetected"
    ],
    "events_consumed": [
     "DeterminationDelivered"
    ],
    "interfaces": [
     "RunQuarterlyPortfolioReview"
    ],
    "depends_on": [
     "review-escalation"
    ],
    "entities": [
     "PortfolioReview"
    ],
    "failure_risks": [
     "A drift pattern missed if review scope excludes older determinations"
    ],
    "scaling": "Scales with annual/quarterly review-cycle volume",
    "future_split_trigger": "Extract to a service only if review assembly becomes a shared multi-tenant bottleneck"
   },
   {
    "name": "rule-matrix",
    "purpose": "Versioned per-jurisdiction rule sets with citation anchors",
    "owned_domain": [
     "RuleMatrixEntry"
    ],
    "application_services": [
     "UpdateRuleMatrix"
    ],
    "infra_adapters": [
     "Regulatory-change diff detector"
    ],
    "public_interfaces": [
     "RuleMatrixVersionPublished event"
    ],
    "forbidden_deps": [
     "Must not depend on any facility-specific data"
    ],
    "responsibility": "Own per-jurisdiction versioned rule sets with citation anchors",
    "owned_data": [
     "RuleMatrixEntry"
    ],
    "events_produced": [
     "RuleMatrixVersionPublished"
    ],
    "events_consumed": [],
    "interfaces": [
     "UpdateRuleMatrix"
    ],
    "depends_on": [],
    "entities": [
     "RuleMatrixEntry"
    ],
    "failure_risks": [
     "Stale rule applied after a regulatory update"
    ],
    "scaling": "Scales with number of jurisdictions, not number of facilities",
    "future_split_trigger": "Extract to a shared service once multiple product lines consume it"
   }
  ],
  "data_architecture": {
   "primary_db": "Postgres (single instance, pilot scale)",
   "secondary": [
    "Encrypted object storage for evidence/memos"
   ],
   "cache": "None required at pilot scale",
   "search": "N/A — citation-linked retrieval only",
   "vector": "Lightweight embedding index over the Requirement Corpus for citation retrieval",
   "object_storage": "Encrypted, per-facility buckets",
   "schema_strategy": "Canonical compliance engagement-request schema versioned with the Requirement Corpus",
   "migrations": "Reviewed, gated migrations; no auto-migrate in production",
   "backups": "Daily encrypted backups, tested quarterly restore",
   "retention": "Engagement-letter-defined retention period",
   "audit_logs": "Append-only, hash-chained per Compliance File",
   "soft_delete": "Used for facility offboarding pending legal-hold check",
   "privacy": "Per-facility row-level isolation; facility benefit-status data heightened handling",
   "encryption": "At-rest and in-transit encryption on all facility/financial data",
   "multi_tenancy": "Logical per-facility isolation via row-level auth, not dedicated infrastructure per facility at pilot scale"
  },
  "api": {
   "style": "Internal service calls only at launch (no public API)",
   "public_vs_internal": "Internal-only",
   "versioning": "N/A at launch",
   "rate_limiting": "Per-tenant concurrency caps on background jobs",
   "idempotency": "Idempotent intake processing keyed on submission ID",
   "pagination": "N/A at launch",
   "error_format": "Structured internal error codes with facility + request ID",
   "webhook_security": "N/A — no external webhooks at launch",
   "retries": "Bounded retries on model calls with circuit breaker",
   "contract_testing": "Contract tests on the canonical schema per submission format",
   "backward_compat": "N/A at launch",
   "contract_testing_plan": "Sample submissions from every pilot facility's format run through contract tests on each schema change"
  },
  "security": {
   "authn": "SSO + MFA for staff",
   "authz": "Server-side role capability checks (Compliance Analyst, Attorney bench, Founder)",
   "tenant_isolation": "Row-level auth + per-facility retrieval partitioning",
   "secrets": "Managed secrets store, no secrets in code or logs",
   "encryption": "At-rest and in-transit on all facility/financial data",
   "session": "Short-lived sessions, MFA-bound",
   "input_validation": "Schema validation on every request field before normalization",
   "api_protection": "N/A — no public API at launch",
   "audit_log": "Append-only, hash-chained, per-request timestamped",
   "admin_access": "Least-privilege, logged, reviewed monthly",
   "supply_chain": "Dependency scanning in CI",
   "threat_model": [
    "Cross-facility data leak",
    "Wrong-verdict determination reaching a facility",
    "Facility/family credential capture (hard-blocked)"
   ],
   "abuse_cases": [
    "A malicious upload attempting prompt injection via a compliance engagement-request or policy document"
   ],
   "zero_trust": "Every internal service call authenticated and authorized, no implicit trust between modules",
   "asvs_notes": "Level 2 controls targeted given sensitive facility financial/benefit-status data classification"
  },
  "reliability": {
   "failure_modes": [
    "Malformed compliance engagement-request submission",
    "Model-call timeout during a portfolio-review volume spike",
    "A required fact missing without notice"
   ],
   "graceful_degradation": "Failed extraction routes to the exception queue rather than blocking the whole cycle",
   "retry_policy": "Bounded retries with exponential backoff on model calls",
   "timeouts": "30s extraction cold-path timeout, else backgrounded",
   "circuit_breaker": "Trips on repeated model-call failures, degrades to manual queue",
   "queueing": "Per-tenant concurrency-capped background job queue",
   "idempotency": "Submission-ID-keyed intake processing",
   "dlq": "Dead-letter queue for failed extraction jobs, reviewed daily",
   "transactions": "One-aggregate-per-transaction boundary",
   "dr": "Daily backups, quarterly restore test",
   "incident_response": "Documented runbook: detect, contain, notify affected facility within 48 hours, root-cause, patch",
   "slos": [
    {
     "name": "Standard determination on-time delivery",
     "target": "100% of standard requests within 1 business day"
    },
    {
     "name": "Free diagnostic turnaround",
     "target": "1 business day"
    }
   ]
  },
  "scaling": {
   "mvp_can_stay_simple": [
    "Single Postgres instance",
    "No public API"
   ],
   "modular_now": [
    "Five domain modules mirroring bounded contexts"
   ],
   "deferrable": [
    "Facility-facing portal",
    "Live IRS data integration",
    "Multi-region deployment"
   ],
   "breaks_first": "Compliance Analyst throughput during a synchronized portfolio-review volume spike across the full cohort",
   "db_path": "Vertical scaling until multi-analyst concurrency requires read replicas",
   "jobs_path": "Add worker concurrency before adding a distributed queue",
   "cache_path": "Introduce caching only if Requirement Corpus retrieval latency becomes a bottleneck",
   "search_path": "N/A at this scale",
   "files_path": "Object storage scales linearly with facilities onboarded",
   "api_path": "Introduce a public API only if a facility case-management integration requires it",
   "multi_region": "Deferred until geographic latency or data-residency requirements emerge",
   "cost_control": "Per-tenant model-spend budget caps"
  },
  "ai": {
   "provider": "Frontier LLM API (model-agnostic per ai-engine-spec.md Model Portability)",
   "prompt_mgmt": "Version-pinned prompts per Requirement Corpus release",
   "rag": "Citation-linked retrieval over the Requirement Corpus",
   "vector": "Lightweight embedding index for citation retrieval",
   "embeddings": "Requirement Corpus citation anchors embedded for retrieval",
   "eval": "Gold-standard regression suite, run on every prompt/rule-matrix version bump",
   "hitl": "Three permanent gates: classification, delivery, certification",
   "guardrails": "Deterministic disclaimer injection; schema validation on every agent output",
   "prompt_injection": "Uploaded documents treated as untrusted data, never instructions",
   "leakage": "Per-facility retrieval partitioning; no cross-facility memory",
   "fallback": "Below-threshold or failed agent output routes to the Exception Queue, never auto-delivers",
   "latency_cost": "Model-call spans tracked per facility per cycle; per-tenant budget caps",
   "memory": "Per-facility, per-request scope; no persistent cross-facility memory",
   "tool_permissions": "Agents can draft and propose; only a human-approved command can deliver",
   "auditability": "Every agent output logged with its confidence score and cited source",
   "citation": "Every determination and every citation references a specific 26 CFR 1.501(r)/state-rule/CHNA QDE source"
  },
  "devops": {
   "environments": [
    "local",
    "preview (per-PR)",
    "staging (shared)",
    "production (single region + multi-AZ)"
   ],
   "observability": [
    "Structured logs with facility + request IDs",
    "RED metrics per workflow",
    "Error tracking with source maps",
    "Model-call spans with cost + latency",
    "Weekly SLO review, with a portfolio-review volume-spike capacity review"
   ],
   "testing_pyramid": [
    "Unit tests on Deterministic Rule Check modules (excise-tax threshold, AGB formula, CHNA cap) and completeness-gate modules",
    "Component tests on the Compliance Analyst exception-queue surfaces",
    "Contract tests on the compliance engagement-request schema per Requirement Corpus jurisdiction entry",
    "End-to-end smoke test on the intake -> classify -> analyst sign-off -> delivery path"
   ],
   "accessibility_tests": [
    "axe-core in CI on analyst-facing surfaces",
    "Keyboard-only walkthrough per workflow",
    "Prefers-reduced-motion honored"
   ],
   "performance_budget": "p95 workflow latency published per module; request extraction cold-path under 30s or shown as a background job.",
   "cicd": "PR -> typecheck + unit + snapshot tests -> preview deploy -> main auto-deploys to a single production region; migrations gated on review.",
   "iac": "Infrastructure as code for the single-region deployment",
   "secrets": "Managed secrets store",
   "preview_envs": "Per-PR preview deploys",
   "migrations": "Reviewed, gated",
   "rollback": "Blue/green deploy with instant rollback",
   "release_style": "Continuous deploy to a single production region on green CI",
   "feature_flags": "Used for Requirement Corpus version rollout per jurisdiction",
   "monitoring": "RED metrics per workflow",
   "alerting": "Paged on any missed-SLA or classification-accuracy anomaly",
   "logs": "Structured, facility + request ID scoped",
   "error_tracking": "Source-mapped error tracking",
   "uptime": "Single-region target 99.5% at pilot scale",
   "cost_monitoring": "Per-tenant model-spend dashboard"
  },
  "testing": {
   "unit": "Deterministic Rule Check and completeness-gate modules",
   "integration": "Cross-module event contracts",
   "contract": "Canonical schema vs. submission formats",
   "e2e": "Intake -> classification -> analyst sign-off -> delivery smoke test",
   "security": "STRIDE-driven test cases per control",
   "a11y": "axe-core on analyst-facing surfaces",
   "load": "Portfolio-review volume-spike simulation",
   "chaos": "Simulated submission-format change",
   "migration": "Schema-migration dry-run against a snapshot of pilot data",
   "backup_restore": "Quarterly restore-test",
   "ai_eval": "Gold-standard regression per Requirement Corpus version bump",
   "test_data": "Synthetic, non-real facility data seeded per jurisdiction"
  },
  "observability": {
   "logs": "Structured, facility + request ID scoped",
   "metrics": "RED per workflow + business events (classification accuracy, determinations delivered)",
   "traces": "Model-call spans with cost + latency",
   "audit_events": "Append-only, hash-chained",
   "business_events": "ComplianceEngagementSubmitted, DeterminationDrafted, RequestEscalated, DeterminationDelivered",
   "error_tracking": "Source-mapped",
   "security_monitoring": "Access-log review, anomaly alerts on cross-facility access attempts",
   "cost_monitoring": "Per-tenant model-spend dashboard",
   "dashboards": [
    "Analyst exception-queue dashboard",
    "Aggregate determinations-delivered / SLA-hit scorecard"
   ],
   "alert_thresholds": [
    "Any determination within 2 hours of its SLA with no analyst action",
    "Classification accuracy below target sustained 2 weeks"
   ],
   "triage": "Analyst on-call reviews any missed-SLA alert within 1 business hour"
  },
  "cost": {
   "drivers": [
    {
     "name": "Model inference",
     "note": "$1-2/determination at day-90 automation"
    },
    {
     "name": "Compliance Analyst review minutes",
     "note": "$8-10/determination, the largest COGS line"
    },
    {
     "name": "Object storage + hosting",
     "note": "$3-5/facility/month"
    }
   ],
   "likely_traps": [
    "Per-facility snowflake integration requests ballooning analyst minutes past the day-90 target"
   ],
   "controls": [
    "Per-tenant model-spend budget caps",
    "Product-vs-custom rule enforced from pilot 1"
   ]
  },
  "multi_tenancy": {
   "model": "Logical multi-tenancy (shared infrastructure, per-facility row-level isolation)",
   "isolation": "Row-level auth + per-facility retrieval partitioning",
   "tenant_aware_authz": "Every query scoped to the requesting analyst's authorized facility set",
   "tenant_config": "Per-facility jurisdiction coverage and retainer configuration",
   "branding": "Internal, analyst-facing branding only — FacilityFile delivers directly to the facility, no facility-facing artifacts",
   "tenant_export": "Full data export available to a facility on offboarding",
   "tenant_deletion": "Deletion SLA per the offboarding SOP, subject to legal hold",
   "tenant_audit": "Per-facility evidence list, independently reconstructable",
   "noisy_neighbor": "Per-tenant concurrency and model-spend caps prevent one facility's volume spike from starving another",
   "tenant_rate_limits": "Per-tenant background-job concurrency caps",
   "billing": "Per-request or monthly retainer billed to the facility, never to a facility or family",
   "why_this_fits": "Pilot scale (5-8 facilities) does not justify dedicated per-facility infrastructure; logical isolation meets the sensitivity bar with far lower operational cost"
  },
  "privacy_compliance": {
   "data_classification": "Facility benefit-status and financial data classified sensitive",
   "minimization": "Only fields required for classification are ingested",
   "consent": "Engagement letter signed by the facility before any request is worked",
   "access_logs": "Reviewed weekly",
   "audit_trails": "Append-only, hash-chained, per-request timestamped",
   "retention": "Engagement-letter-defined retention period",
   "legal_hold": "Deletion paused under an active legal hold",
   "right_to_delete": "Honored per the offboarding SOP absent a legal hold",
   "right_to_export": "Full export delivered to the facility on offboarding",
   "sensitive_handling": "Facility benefit-status records get heightened handling",
   "boundaries": "No facility/family credentials ever collected; no custody of 501(r) funds; no fees billed to individual patients or families",
   "residency": "US-only storage at pilot scale",
   "vendor_risk": "LLM API vendor reviewed for data-use terms; no training on customer data",
   "breach_response": "48-hour affected-facility notification runbook",
   "admin_controls": "Least-privilege, logged, reviewed monthly",
   "evidence_collection": "Hash-chained snapshots support forensic reconstruction if needed"
  },
  "frontend": {
   "framework": "Lightweight internal console (React or equivalent) for the analyst exception queue only",
   "rendering": "Server-rendered where practical; no facility-facing app",
   "routing": "Internal routes only",
   "state": "Minimal — queue state and form state",
   "server_state": "Fetched per analyst session",
   "forms": "Analyst review/approval forms with explicit labels",
   "error_handling": "Inline validation with clear next-step messaging",
   "components": "Exception-queue list, determination detail, approval action buttons",
   "design_system": "Shared internal component set, no public design system needed at launch",
   "auth_ui": "SSO login only",
   "authz_aware_ui": "UI hides actions the logged-in role cannot perform",
   "a11y": "Keyboard-complete, axe-core in CI",
   "i18n": "en-US only",
   "performance": "Not conversion-critical (internal tool); still budget-conscious",
   "bundling": "Standard bundler, no special constraints",
   "testing": "Component tests on the exception-queue surface",
   "offline": "Not required",
   "realtime": "Not required at pilot scale"
  },
  "backend": {
   "framework": "Typed service layer (e.g., Node/TypeScript or Python) per domain module",
   "layering": "domain / application / infra per module",
   "domain": "Aggregates and value objects per ddd.aggregates",
   "services": "Application services per bounded context (see ddd.bounded_contexts)",
   "repositories": "Per-facility-partitioned repositories per aggregate",
   "validation": "Schema validation at every module boundary",
   "authorization": "Server-side capability checks per role",
   "jobs": "Background extraction/classification jobs, per-tenant concurrency capped",
   "events": "In-process domain event dispatch (see ddd.context_map)",
   "files": "Encrypted object storage adapters",
   "email_sms": "Secure email send adapter (analyst-approved only)",
   "scheduled": "SLA timers (1-business-day standard, 4-hour rush)",
   "errors": "Structured error codes with facility + request ID",
   "logging": "Structured logs, PII-scrubbed",
   "config": "Environment-scoped config, secrets in a managed store",
   "di": "Constructor-based dependency injection per module",
   "testing": "Unit + component + contract + e2e per ddd.testing_strategy"
  },
  "diagrams": {
   "context_mermaid": "graph LR; Facility-->|compliance engagement|Intake; Intake-->|RequestDataNormalized|Determination; Determination-->|DeterminationDrafted|ReviewEscalation; ReviewEscalation-->|DeterminationDelivered|PortfolioCompliance; RuleMatrix-->Determination; RuleMatrix-->PortfolioCompliance",
   "container_mermaid": "graph TD; AnalystConsole-->AppServices; AppServices-->Postgres; AppServices-->ObjectStorage; AppServices-->LLMAPI",
   "data_flow_mermaid": "graph LR; ComplianceEngagement-->Extraction-->CanonicalSchema-->Classification-->ComplianceFile-->EscalationCase-->PortfolioReview",
   "auth_flow_mermaid": "sequenceDiagram; Analyst->>SSO: authenticate; SSO->>Console: session token (MFA-bound)",
   "authz_flow_mermaid": "sequenceDiagram; Console->>AppServices: action request; AppServices->>RoleCheck: verify capability; RoleCheck-->>AppServices: allow/deny",
   "deployment_mermaid": "graph TD; PR-->Preview; Preview-->Staging; Staging-->Production_SingleRegion",
   "background_job_mermaid": "graph LR; IntakeQueue-->ExtractionWorker-->ClassificationWorker-->ExceptionQueue",
   "event_flow_mermaid": "graph LR; DeterminationDrafted-->AnalystReview-->EscalationCheck-->DeliverOrEscalate",
   "failure_flow_mermaid": "graph LR; MalformedSubmission-->ExceptionQueue-->AnalystReview-->Resolved_or_Escalated",
   "multi_tenant_flow_mermaid": "graph LR; FacilityA_Data-->RowLevelAuth; FacilityB_Data-->RowLevelAuth; RowLevelAuth-->PerFacilityPartition",
   "ai_flow_mermaid": "graph LR; Submission-->ExtractionAgent-->ClassificationAgent-->DraftingAgent-->AnalystGate-->Deliver"
  },
  "adrs": [
   {
    "id": "ADR-001",
    "decision": "Launch as a single-region modular monolith, not microservices",
    "status": "accepted",
    "context": "A 5-8-account pilot cap does not justify microservice operational overhead",
    "options": [
     "Modular monolith",
     "Microservices",
     "No-code workflow tool"
    ],
    "chosen": "Modular monolith",
    "business_reason": "Fastest path to the first 3-5 pilot determinations without a platform team",
    "technical_reason": "Module boundaries mirror bounded contexts, keeping a future split cheap",
    "tradeoffs": "Less independent scalability per module until volume demands it",
    "risks": [
     "[PLACEHOLDER] owner to complete"
    ],
    "revisit_trigger": "Sustained load beyond the analyst-throughput target",
    "why": "Matches the actual pilot scale",
    "consequences": [
     "[PLACEHOLDER] owner to complete"
    ],
    "reversal": "Extract a module to a service if its load profile diverges sharply",
    "revisit_when": "Post-20-pilot pause-and-measure checkpoint"
   },
   {
    "id": "ADR-002",
    "decision": "No facility-facing portal at launch; delivery is email/document only",
    "status": "accepted",
    "context": "The blueprint's sales thesis is that the facility never operates software",
    "options": [
     "Build a facility-facing dashboard",
     "Email/document delivery only",
     "White-labeled third-party portal"
    ],
    "chosen": "Email/document delivery only",
    "business_reason": "Matches the 'we sell a determination, not a dashboard' positioning",
    "technical_reason": "Removes an entire authn/authz surface at pilot scale",
    "tradeoffs": "No self-serve visibility for the facility between determinations",
    "risks": "A facility used to a dashboard may perceive the service as less real-time",
    "revisit_trigger": "Multiple pilot facilities request live status visibility",
    "why": "Keeps the MVP thin and evidence-linked",
    "consequences": "Delivered memos and readout calls carry the full trust burden",
    "reversal": "Add a lightweight read-only status view if demand is proven",
    "revisit_when": "After the 10-pilot hardening checkpoint"
   }
  ],
  "roadmap": [
   {
    "phase": "Phase 0 — Stand up the operating spine",
    "weeks": "Week 1 (Days 1-7)",
    "outcomes": [
     "Requirement Corpus v0 (founder's home state + federal 26 CFR 1.501(r) baseline) built and attorney-reviewed",
     "Facility Readiness Scan landing page + intake form live and tested",
     "Engagement-letter template drafted; TEO Attorney/TEO attorney-bench relationship opened; 5 warm outreaches sent"
    ],
    "exit_criteria": [
     "One full test determination processed end-to-end on sample data",
     "Counsel sign-off on the engagement-letter template",
     "Intake mailbox tested with one dummy submission"
    ],
    "kill_criteria": [
     "Any operating-spine item not ready by Day 7 — outreach held even if it slips past Day 7"
    ],
    "build": [
     "Requirement Corpus v0",
     "Exception-queue console",
     "SLA timers"
    ],
    "defer": [],
    "monitor": [
     "Auto-classification accuracy",
     "Benefit-suspension incidents",
     "Analyst review minutes"
    ],
    "avoid": [
     "Building a facility-facing portal before the 20-pilot checkpoint proves margin"
    ],
    "acceptable_debt": [
     "[PLACEHOLDER] owner to complete"
    ],
    "dangerous_debt": [
     "[PLACEHOLDER] owner to complete"
    ],
    "triggers_to_change": [
     "[PLACEHOLDER] owner to complete"
    ]
   },
   {
    "phase": "Phase 1 — Onboard the pilot cohort, run the first determinations",
    "weeks": "Weeks 2-4 (Days 8-30)",
    "outcomes": [
     "First 3-5 paid pilot determinations delivered manually",
     "Attorney-bench agreement signed",
     "3 educational content pieces published",
     "Requirement Corpus expanded to 3-5 states based on actual pilot footprint"
    ],
    "exit_criteria": [
     "Pilot cap enforced at 5-8 accounts regardless of inbound demand",
     "Founder personally reviews every exception before delivery",
     "Exception queue and communications log stood up"
    ],
    "kill_criteria": [
     "Fewer than 3 signed pilots after 30 days of qualified outreach",
     "No willingness-to-engage signal above the free-diagnostic offer"
    ],
    "build": [
     "Pilot intake + engagement-letter flow"
    ],
    "defer": [],
    "monitor": [
     "Auto-classification accuracy",
     "Benefit-suspension incidents",
     "Analyst review minutes"
    ],
    "avoid": [
     "Building a facility-facing portal before the 20-pilot checkpoint proves margin"
    ],
    "acceptable_debt": "Manual Requirement Corpus spreadsheet for the first 5-10 pilots",
    "dangerous_debt": "Per-facility classification logic that can't be expressed as a rule",
    "triggers_to_change": "Sustained analyst review time above the day-90 target for 2 consecutive cycles"
   },
   {
    "phase": "Phase 2 — Hold the cap, prove the model",
    "weeks": "Weeks 5-8 (Days 31-60)",
    "outcomes": [
     "5-8-account pilot cap reached",
     "AI drafting layer introduced against a growing adjudicated-example library, 100% analyst review retained",
     "First Annual Compliance File subscription conversions",
     "5-pilot hardening checkpoint completed"
    ],
    "exit_criteria": [
     "1-business-day standard turnaround hit on every determination",
     "Zero benefit-suspension incidents traced to a delivered determination",
     "TEO Attorney Determination delivered on at least 1 escalated case"
    ],
    "kill_criteria": [
     "Pilot-cohort diagnostic-to-paid conversion stalls far below target",
     "Rework rate persistently above 5%"
    ],
    "build": [
     "AI drafting layer against a growing adjudicated-example library"
    ],
    "defer": [],
    "monitor": [
     "Auto-classification accuracy",
     "Benefit-suspension incidents",
     "Analyst review minutes"
    ],
    "avoid": [
     "Building a facility-facing portal before the 20-pilot checkpoint proves margin"
    ],
    "acceptable_debt": "Manual Requirement Corpus spreadsheet for the first 5-10 pilots",
    "dangerous_debt": "Per-facility classification logic that can't be expressed as a rule",
    "triggers_to_change": "Sustained analyst review time above the day-90 target for 2 consecutive cycles"
   },
   {
    "phase": "Phase 3 — Formalize SOPs, evaluate the 10-pilot checkpoint",
    "weeks": "Weeks 9-13 (Days 61-90)",
    "outcomes": [
     "Second Compliance Analyst certified independent of the founder",
     "Written SOPs, escalation matrix, and QA sampling rules formalized",
     "System Portfolio Review piloted with at least 1 account",
     "90-day retrospective completed; 10-pilot checkpoint evaluated with real data"
    ],
    "exit_criteria": [
     "Analyst shadows Founder on at least 5 live determinations before unsupervised exception review",
     "10-pilot hardening checklist complete (intake spec, evidence requirements, QA checklists)",
     "Gross margin trending toward the blueprint's 50-55% target"
    ],
    "kill_criteria": [
     "Escalation-to-attorney rate exceeds 30% with no improving trend",
     "Analyst review time not declining by pilot 15-20"
    ],
    "build": [
     "Second-analyst certification"
    ],
    "defer": [],
    "monitor": [
     "Auto-classification accuracy",
     "Benefit-suspension incidents",
     "Analyst review minutes"
    ],
    "avoid": [
     "Building a facility-facing portal before the 20-pilot checkpoint proves margin"
    ],
    "acceptable_debt": "Manual Requirement Corpus spreadsheet for the first 5-10 pilots",
    "dangerous_debt": "Per-facility classification logic that can't be expressed as a rule",
    "triggers_to_change": "Sustained analyst review time above the day-90 target for 2 consecutive cycles"
   }
  ],
  "anti_overengineering": {
   "flagged": [
    {
     "item": "Facility-facing portal at launch",
     "why": "No pilot facility has asked for self-serve access; the sales thesis is 'the facility never operates a tool'",
     "simpler": "Email/document delivery + readout calls"
    },
    {
     "item": "Microservices architecture",
     "why": "A 5-8-account pilot cap does not generate load requiring independent service scaling",
     "simpler": "Modular monolith with clean module boundaries mirroring bounded contexts"
    },
    {
     "item": "Live IRS data integration",
     "why": "1-business-day cadence does not require live sync; adds integration-project overhead the MVP explicitly avoids",
     "simpler": "Facility-supplied benefit-status confirmation at intake"
    }
   ]
  },
  "risks": [
   {
    "risk": "Compliance Analyst bottleneck during a synchronized portfolio-review spike",
    "likelihood": "medium",
    "impact": "high",
    "mitigation": "Certify a second analyst after 5-10 pilots; stagger onboarding cohorts where possible",
    "detection": "Exception-queue backlog alert",
    "owner": "owner",
    "escalation": "Founder personally backstops until a second analyst is certified",
    "fallback": "Temporarily pause new-facility onboarding",
    "category": "operational"
   },
   {
    "risk": "Submission-format change breaks the Extraction Agent silently",
    "likelihood": "medium",
    "impact": "medium",
    "mitigation": "Contract tests per submission format; confidence-score drop alerting",
    "detection": "Extraction confidence-score drop alert",
    "owner": "engineering",
    "escalation": "Engineering Lead patches the parser within 48 hours",
    "fallback": "Manual extraction for the affected facility until patched",
    "category": "technical"
   },
   {
    "risk": "A state bar objects to the non-certified tier's positioning",
    "likelihood": "low-medium",
    "impact": "high",
    "mitigation": "Counsel-reviewed engagement-letter scoping before the first paid engagement; escalation criteria route borderline cases automatically",
    "detection": "Counsel's periodic regulatory scan",
    "owner": "legal",
    "escalation": "Counsel advises routing 100% of engagements through attorney sign-off temporarily",
    "fallback": "Certified-only operating mode until the boundary is resolved",
    "category": "regulatory"
   }
  ],
  "rules": [
   "No dollar figure is ever computed by the model — all money math is deterministic code",
   "No Compliance File ships without a Compliance Analyst approval",
   "No facility/family credential is ever collected, stored, or requested"
  ],
  "audit": {
   "product_fit": 5,
   "simplicity": 4,
   "security": 4,
   "reliability": 4,
   "scalability": 4,
   "maintainability": 4,
   "performance": 4,
   "cost": 4,
   "compliance": 4,
   "dx": 4,
   "ops_burden": 4,
   "extensibility": 4,
   "team_suitability": 4,
   "time_to_market": 5,
   "recommendation": {
    "verdict": "Proceed — single-region modular monolith is the right-sized architecture for a 5-8-account pilot",
    "stack": "Typed backend service layer + Postgres + encrypted object storage + frontier LLM API",
    "style": "Modular monolith",
    "database": "Postgres, row-level partitioned",
    "hosting": "Single-region, multi-AZ",
    "auth": "SSO + MFA",
    "ai_approach": "Retrieval-first, citation-linked, deterministic-rules-backed agents with a permanent human-plus-attorney approval gate",
    "integrations": "Email/upload intake, secure email delivery, encrypted object storage",
    "build_first": [
     "Requirement Corpus v0 for federal 26 CFR 1.501(r) + founder's home state",
     "Exception-queue console"
    ],
    "revisit_later": [
     "Facility-facing portal",
     "Live IRS data integration"
    ],
    "avoid": [
     "Microservices before a few dozen facilities per analyst",
     "Public API before a partner integration requires it"
    ],
    "biggest_risks": [
     "Compliance Analyst bottleneck at a synchronized volume spike",
     "Submission-format change breaking extraction silently"
    ],
    "top_10_rules": [
     "No dollar figure is ever computed by the model — all money math is deterministic code",
     "No Compliance File ships without a Compliance Analyst approval",
     "No facility/family credential is ever collected, stored, or requested",
     "Row-level auth on every query",
     "Append-only audit log on every state transition",
     "Attorney sign-off required on every TEO Attorney Determination"
    ],
    "first_10_steps": [
     "Stand up the intake mailbox, engagement-letter template, and Facility Readiness Scan landing page",
     "Populate the owner-action ledger with entity, jurisdiction, contact inbox, privacy inbox",
     "Open founding-pilot intake (cap 5-8) with an explicit free-diagnostic conversation",
     "Write the home-state-first, multi-state-second sequencing and kill/pivot criteria into the launch plan",
     "Codify federal 26 CFR 1.501(r) into the Requirement Corpus v0 with citation anchors",
     "Wire the append-only audit log + hash-chained Compliance File snapshots",
     "Add row-level auth + facility-scoped retrieval indices",
     "Instrument diagnostic-request, determination-delivered, and analyst-sign-off events",
     "Publish the microsite noindexed until owner-action facts close",
     "Schedule the Day-90 kill/pivot review with the Founder"
    ]
   }
  }
 },
 "design": {
  "slug": "501r-community-benefit-compliance-engine",
  "archetypes": [
   "compliance determination desk",
   "elder & disability-benefits advisory-adjacent service"
  ],
  "user_mindset": {
   "goals": "Confirm a proposed compliance engagement is safe and get a citable record fast",
   "session_length": "Short, task-focused (a determination request, a readout, a portfolio review read)",
   "confidence": "Wants precision (citations, dollar impact, dates), not reassurance language",
   "interface_needs": "Scannable verdict at a glance; no jargon; clear next action"
  },
  "posture": [
   "Quiet authority",
   "Citation-first",
   "Facility-branded warmth is not needed — FacilityFile is the buyer's own internal desk, not a family-facing product"
  ],
  "density": "Medium — enough white space to read calmly, enough data density to feel like a real compliance file, not a marketing page pretending to be a dashboard",
  "trust_level": {
   "tier": "high — handles facility benefit-status data and remittance financial data",
   "sensitive_domains": [
    "Facility AGB/Schedule H/IRS enrollment status",
    "Policy and remittance financial data"
   ],
   "implications": [
    "Every claim must be sourced or marked [PLACEHOLDER]",
    "No decorative motion or gamified UI patterns"
   ]
  },
  "differentiation": {
   "avoid": [
    "Insurtech/fintech gradient hero clichés",
    "Stock elderly-couple or wheelchair-user imagery",
    "Countdown-timer urgency gimmicks that read as pressure rather than information"
   ],
   "strategy": "Citation-precise, benefits-law-specific visual language: a verdict strip, Deterministic Rule Check badges, and a determination-memo structure rendered as real artifacts, not abstract icons"
  },
  "territories": [
   {
    "name": "Ledger Guardian",
    "color_mood": "deep indigo-navy brand, warm paper surface, amber-gold accent",
    "typography": "System serif-adjacent display, clean sans body",
    "density": "medium",
    "component_feel": "Determination-memo precision — verdict badges, citations, real dates",
    "motion": "Minimal, functional only",
    "fits": "A buyer who wants proof and liability protection, not persuasion",
    "risks": "Could read as plain if not paired with sharp, specific copy"
   },
   {
    "name": "Alarm Fintech",
    "color_mood": "red/orange urgency, dark dashboard chrome",
    "typography": "Bold condensed display",
    "density": "high",
    "component_feel": "Countdown timers, flashing badges",
    "motion": "Pulsing alerts",
    "fits": "A buyer who responds to fear",
    "risks": "Reads as pressure-selling to a facility already carrying real personal liability — banned by DESIGN-STANDARD anti-corruption rule"
   },
   {
    "name": "Generic SaaS",
    "color_mood": "blue/purple gradient",
    "typography": "Default startup sans",
    "density": "low",
    "component_feel": "Rounded cards, soft shadows",
    "motion": "Hover-lift everywhere",
    "fits": "Nothing specific to this business",
    "risks": "Visually confusable with any other launched business — banned by DESIGN-STANDARD §9"
   }
  ],
  "chosen_territory": "Ledger Guardian",
  "chosen_rationale": "The buyer is a hospital facility evaluating whether to trust a service with a facility's compliance status and their own facility liability; precision and calm authority convert better than urgency theater, and the deep indigo/amber palette is visually distinct from both the freight business's navy/burnt-orange industrial palette and the ESA business's pine-teal/berry palette.",
  "prioritized_components": [
   {
    "name": "Verdict strip",
    "why": "Makes the three-outcome determination (approve/approve-with-conditions/do-not-disburse) tangible at a glance"
   },
   {
    "name": "Deterministic Rule Check badge",
    "why": "Uses the --state-* tokens to make a deterministic rule outcome legible without alarming color"
   },
   {
    "name": "Compliance File preview card",
    "why": "Shows the actual deliverable shape, building trust before purchase"
   },
   {
    "name": "Citation chip",
    "why": "Signals the 26 CFR 1.501(r)/state-rule precision that differentiates from a generic AI chatbot answer"
   },
   {
    "name": "Pricing card with guarantee inline",
    "why": "Puts the turnaround guarantee and non-guarantee disclaimer where risk perception peaks, per DESIGN-STANDARD §8"
   },
   {
    "name": "FAQ disclosure list",
    "why": "Handles real objections without a wall of text"
   }
  ],
  "tokens": {
   "brand": "222 46% 24%",
   "brand-fg": "0 0% 100%",
   "surface": "45 22% 96%",
   "ink": "222 32% 12%",
   "muted": "222 12% 36%",
   "accent": "36 82% 32%"
  },
  "type": {
   "display": "system-ui, 'Georgia', serif fallback for headings",
   "body": "system-ui, -apple-system, 'Segoe UI', sans-serif",
   "fonts_url": "none — system font stack only, no external font requests"
  },
  "signature": {
   "motif": "A verdict strip (Approve / Approve with conditions / Do not disburse) rendered with the four domain-state tokens, echoed in miniature across the hero, pricing, and playbook artifacts",
   "render": "Three badge chips in a horizontal row, colored by --state-ok/--state-pending/--state-blocked, with a citation chip beneath the active verdict"
  },
  "patterns": [
   {
    "name": "Status badge",
    "description": "A pill using the four --state-* tokens (ok/risk/pending/blocked) for any determination or review status, never a raw color"
   },
   {
    "name": "Citation chip",
    "description": "A small inline tag citing the specific 26 CFR 1.501(r) section, state rule, or CHNA QDE guidance for any factual claim in a memo or on the page"
   },
   {
    "name": "Placeholder proof slot",
    "description": "A dashed-border card honestly labeled [PLACEHOLDER] and keyed to a real future event, never a fabricated result"
   }
  ],
  "states": [
   "ok — approved / reconciled and on file",
   "risk — dollar-at-risk or do-not-disburse flag",
   "pending — awaiting analyst or attorney review",
   "blocked — escalated / exception-queue status"
  ],
  "uniqueness_audit": {
   "app_specific_decisions": [
    "Verdict-strip motif tied to the exact three-outcome determination structure",
    "Citation-chip pattern unique to the 26 CFR 1.501(r)/state-rule-heavy classification workflow"
   ],
   "cliches_avoided": [
    "No countdown-timer alarm styling",
    "No stock elderly-couple/wheelchair photography",
    "No generic 'AI dashboard' gradient hero"
   ],
   "scale_notes": "Palette and components scale from a single-page microsite to an internal analyst console without a re-theme."
  },
  "localization": [
   "en-US only at launch; no locale-specific formatting required"
  ]
 },
 "seo": {
  "slug": "501r-community-benefit-compliance-engine",
  "archetype": "vertical compliance-determination desk / diagnostic-led service site",
  "archetype_impact": "Ranks primarily on benefits-mechanics questions (AGB excise-tax threshold, AGB formula, CHNA QDE) rather than generic 'AI compliance' terms.",
  "authority_dna": {
   "site_archetype": "single-vertical service site with a free-diagnostic lead magnet",
   "monetization_model": "per-request fee + portfolio retainer subscription + flat certified-opinion fee",
   "main_search_intents": [
    "informational (benefits-mechanics questions)",
    "commercial (compliance engagement compliance determination service)"
   ],
   "topical_authority_opportunity": "501(r) compliance engagement-compliance mechanics content is thin and scattered across nonprofit fact sheets and tax-exempt-organizations blog posts — a citation-rich, maintained explainer set can own this niche quickly",
   "local_seo_opportunity": "Low — buyers search benefits-mechanics terms nationally, not 'near me'",
   "global_national_opportunity": "National within the US AGB/IRS/CHNA framework; state-specific content clusters added as the Requirement Corpus expands",
   "easiest_ranking_path": "Long-tail benefits-mechanics questions with low current competition ('can a hospital facility pay for a vacation')",
   "hardest_ranking_path": "Broad terms like 'hospital facility' or 'hospital facility' dominated by nonprofit and fintech incumbents",
   "trust_credibility_requirements": [
    "Citations to primary 26 CFR 1.501(r)/IRS/CHNA NRC sources",
    "Clearly named entity (FacilityFile) so assistants attribute answers",
    "No fabricated statistics — every figure traces to a Verified source"
   ],
   "ymyl": true,
   "expert_review_needed": true,
   "site_structure": "Flat: homepage -> a small set of benefits-mechanics pillar pages -> FAQ/glossary supporting pages -> /blueprint/ dossier",
   "seo_moat": "Citation-anchored, continuously updated benefits-mechanics content that AI assistants can quote with a named source"
  },
  "search_market": {
   "primary_markets": [
    "Professional facilities and compliance officers",
    "Health-law and healthcare CPA advisory firms",
    "Multi-facility health system administrators"
   ],
   "secondary_markets": [
    "CHNA state program administrators",
    "Personal-injury attorneys establishing single-facility engagements"
   ],
   "low_competition_subtopics": [
    "AGB-percentage formula worked examples",
    "2026 CHNA age expansion mechanics for facilitys",
    "Type A vs Type B FAP contract differences"
   ],
   "high_commercial_intent": [
    "hospital facility compliance engagement compliance service",
    "free facility readiness scan",
    "hospital facility compliance determination"
   ],
   "informational": [
    "can a hospital facility pay for a vacation",
    "will this compliance engagement affect AGB",
    "what is a qualified community-benefit expense for CHNA"
   ],
   "local_intent": [],
   "transactional": [
    "compliance engagement compliance review service",
    "hospital facility compliance desk"
   ],
   "comparison": [
    "FacilityFile vs True Link Financial",
    "in-house benefits review vs outsourced determination desk"
   ],
   "problem_solution": [
    "accidentally overpaid hospital facility distribution",
    "AGB miscalculated after a facility compliance engagement"
   ],
   "near_me": [],
   "long_tail": [
    "what happens when a facility misses its CHNA deadline",
    "able account medicaid payback explained",
    "2026 able age adjustment act who is now eligible"
   ],
   "questions": [
    "is a compliance engagement compliance desk allowed under ssa rules",
    "who signs off on a hospital facility distribution determination",
    "how much does a hospital facility charge per compliance engagement"
   ],
   "emerging": [
    "AGB Savings Penalty Elimination Act tracking",
    "CHNA age-expansion caseload growth for facilitys"
   ],
   "seasonal": [],
   "underserved_serps": [
    "AGB AGB-percentage worked dollar examples",
    "System Portfolio vs single-facility differences"
   ],
   "weak_serps": [
    "hospital facility fee comparison"
   ],
   "forum_dominated_serps": [
    "reddit/facebook special needs parent group discussions of AGB overpayment notices"
   ],
   "winnable_authoritative_serps": [
    "AGB resource-limit and AGB formula explainer",
    "2026 September 2025 Ways & Means hearing explainer for facilitys"
   ],
   "avoid_initially": [
    "Broad 'disability benefits policy' debate content — not the buyer's search intent"
   ],
   "easy_wins": [
    "$50,000 resource-limit explainer",
    "AGB AGB-percentage worked example",
    "2026 CHNA age expansion explainer"
   ],
   "moderate": [
    "System Portfolio vs single-facility guide",
    "TEO Attorney Determination / UPL-boundary explainer"
   ],
   "long_term_plays": [
    "Multi-state IRS-supplement mechanics hub as Requirement Corpus coverage grows"
   ],
   "do_not_pursue": [
    "General disability-rights policy commentary",
    "Political benefits-reform debate content"
   ]
  },
  "keyword_clusters": [
   {
    "primary": "facility readiness scan hospital facility",
    "related": [
     "free facility readiness scan",
     "able account compliance review"
    ],
    "intent": "commercial",
    "user_problem": "Doesn't know if a proposed compliance engagement is safe to approve",
    "funnel": "top",
    "business_value": "high",
    "ranking_difficulty": "low",
    "conversion_potential": "high",
    "content_effort": "medium",
    "serp_weakness": "no incumbent owns this exact phrase",
    "local_relevance": "national",
    "global_relevance": "national",
    "suggested_page_type": "landing page",
    "reason": "Direct match to the flagship lead magnet",
    "priority_score": 95,
    "priority": "high",
    "bucket": "primary"
   },
   {
    "primary": "can a hospital facility pay for X",
    "related": [
     "501(r) allowable community-benefit expenses",
     "what counts toward a facility's community-benefit spending"
    ],
    "intent": "informational",
    "user_problem": "Doesn't know if a specific expense is safe",
    "funnel": "top",
    "business_value": "high",
    "ranking_difficulty": "low",
    "conversion_potential": "medium",
    "content_effort": "low",
    "serp_weakness": "thin, scattered coverage",
    "local_relevance": "national",
    "global_relevance": "n/a",
    "suggested_page_type": "pillar article",
    "reason": "High-intent, mechanics-specific, low competition",
    "priority_score": 90,
    "priority": "high",
    "bucket": "primary"
   },
   {
    "primary": "2026 CHNA age adjustment act explained",
    "related": [
     "able eligibility age 46",
     "able age expansion facility guide"
    ],
    "intent": "informational",
    "user_problem": "Facility doesn't know their caseload just expanded",
    "funnel": "top",
    "business_value": "high",
    "ranking_difficulty": "low",
    "conversion_potential": "medium",
    "content_effort": "low",
    "serp_weakness": "coverage exists but not organized for facilitys",
    "local_relevance": "national",
    "global_relevance": "n/a",
    "suggested_page_type": "pillar article",
    "reason": "Timed to the January 2026 eligibility expansion",
    "priority_score": 88,
    "priority": "high",
    "bucket": "secondary"
   }
  ],
  "topical_authority_map": {
   "core_topics": [
    "26 CFR 1.501(r) FAP and AGB mechanics",
    "hospital facility QDE and eligibility mechanics",
    "501(r) compliance as a discipline"
   ],
   "pillars": [
    {
     "name": "AGB & CHNA Compliance Engagement Mechanics Hub",
     "core_intent": "informational -> commercial",
     "audience": "Professional facilities and compliance officers",
     "conversion_goal": "Facility Readiness Scan request",
     "supporting_pages": [
      "$50,000 resource-limit explainer",
      "AGB AGB-percentage worked example",
      "2026 CHNA age expansion explainer"
     ],
     "internal_links": [
      "/",
      "/blueprint/"
     ],
     "schema": [
      "FAQPage",
      "Article"
     ],
     "evidence_needed": [
      "IRS 26 CFR 1.501(r) citation",
      "IRS Tax-Exempt & Government Entities division citation"
     ],
     "local_variants": [],
     "national_variants": [
      "State IRS-Supplement Mechanics Hub"
     ]
    }
   ],
   "supporting_page_types": [
    "Benefits-mechanics explainer",
    "Worked dollar example (diagnostic teardown)",
    "FAQ/glossary page",
    "TEO Attorney Determination / UPL-boundary explainer",
    "State IRS-supplement variant page"
   ]
  },
  "site_architecture": {
   "homepage_strategy": "Single conversion-focused landing page; benefits-mechanics depth lives in supporting content, not the homepage",
   "main_nav": [
    "How it works",
    "Pricing",
    "Get your Check"
   ],
   "footer_nav": [
    "View the full operating blueprint dossier",
    "Compliance & licensing boundary"
   ],
   "hubs": [
    {
     "name": "AGB & CHNA Compliance Engagement Mechanics Hub",
     "purpose": "Own benefits-mechanics search intent and feed the diagnostic-check CTA",
     "url": "/501r-community-benefit-compliance-engine/compliance engagement-mechanics"
    }
   ],
   "url_patterns": [
    "/501r-community-benefit-compliance-engine/{topic-slug}"
   ],
   "avoid_url_patterns": [
    "Deep nested category URLs unneeded at this content volume"
   ]
  },
  "global_national": {
   "national_clusters": [
    "Multi-state IRS-supplement mechanics hub as Requirement Corpus coverage grows"
   ],
   "linkable_assets": [
    "The 501(r) Compliance Engagement Red-Flag Checklist (downloadable)"
   ],
   "original_research_ideas": [
    "Anonymized aggregate 'common compliance engagement mistake' pattern memos drawn from pilot-cohort exception data"
   ],
   "international_needed": false,
   "international_notes": "US-only program; no international relevance"
  },
  "local_seo": {
   "justified": false,
   "reason": "Buyers search by federal/state benefits program, not by city/proximity",
   "gbp_categories_primary": [],
   "gbp_categories_secondary": [],
   "location_page_rules": [],
   "citations": [],
   "review_strategy": "No fabricated reviews; testimonials only after real pilot outcomes exist, per DESIGN-STANDARD §9",
   "local_schema": []
  },
  "programmatic": {
   "recommended": false,
   "reason": "Content volume and buyer count at pilot scale don't justify programmatic page generation; risk of thin-content penalties outweighs benefit",
   "rules": [],
   "per_page_requirements": [],
   "quality_gates": []
  },
  "page_templates": [
   {
    "page_type": "Benefits-mechanics pillar article",
    "purpose": "Own a specific compliance-mechanics question",
    "target_intent": "informational -> commercial",
    "url_pattern": "/501r-community-benefit-compliance-engine/{mechanic}",
    "title_pattern": "{Mechanic} explained: what facilitys must know",
    "meta_description_pattern": "{Mechanic} in plain language, with the exact citation, plus a free Facility Readiness Scan to verify your own case.",
    "h1_pattern": "{Mechanic}: the compliance math",
    "outline": [
     "What the rule says (cited)",
     "Why it costs a facility benefits if mishandled",
     "A worked dollar example",
     "How FacilityFile enforces it",
     "FAQ",
     "Diagnostic Check CTA"
    ],
    "above_the_fold": [
     "[PLACEHOLDER] owner to complete"
    ],
    "internal_links": [
     "/"
    ],
    "schema": [
     "Article",
     "FAQPage"
    ],
    "cta_strategy": "Diagnostic Check request after the worked example",
    "conversion_elements": [
     "Inline diagnostic CTA",
     "Verdict-strip visual"
    ],
    "trust_elements": [
     "Primary-source citation",
     "Compliance disclaimer"
    ],
    "faq_opportunities": [
     "Is this allowed under IRS's own rules?"
    ],
    "media": [
     "[PLACEHOLDER] owner to complete"
    ],
    "quality_requirements": [
     "Every citation traces to a primary source"
    ],
    "anti_thin_rules": [
     "No page ships without a worked dollar example and a citation"
    ]
   }
  ],
  "on_page_rules": {
   "title_tag": "Under 60 characters, leads with the mechanic or outcome, never 'AI-Native Blueprint'",
   "meta_description": "Under 155 characters, states the concrete outcome and cites a real figure",
   "headings": "One H1 per page, ordered H2/H3",
   "intro": "States the rule/answer in the first two sentences",
   "snippet_targeting": "Direct Q&A format for featured-snippet eligibility",
   "tables_lists": "Dollar figures and thresholds in tables where possible",
   "images": "Verdict-strip diagrams with meaningful alt text",
   "internal_links": "Every pillar links to the Diagnostic Check CTA and the blueprint dossier",
   "external_citations": "Primary source (26 CFR 1.501(r), IRS, CHNA NRC) cited on every factual claim",
   "author_attribution": "Founder byline with program-expertise framing",
   "freshness": "Dated 'last verified' line, re-checked each legislative session",
   "cta_placement": "After the worked example and again at the page end",
   "mobile": "Single-column, no horizontal scroll",
   "avoid": [
    "Keyword stuffing",
    "Unsourced statistics"
   ]
  },
  "entity_seo": {
   "main_entities": [
    "FacilityFile",
    "Compliance File",
    "Facility Readiness Scan"
   ],
   "related_entities": [
    "Social Security Administration (IRS)",
    "IRS Tax-Exempt & Government Entities division",
    "26 CFR 1.501(r)",
    "IRC §501(r)"
   ],
   "people": [
    "Founder (role-title only, no fabricated bio claims)"
   ],
   "orgs": [
    "Social Security Administration",
    "IRS Tax-Exempt & Government Entities division",
    "CPT Institute",
    "True Link Financial"
   ],
   "tools": [
    "Requirement Corpus"
   ],
   "regulations": [
    "IRS 26 CFR 1.501(r) / SI 02301.205 / SI 01130.740",
    "IRC §501(r) (CHNA Act, as amended by the September 2025 Ways & Means hearing)"
   ],
   "problems": [
    "AGB AGB-percentage AGB reduction",
    "$50,000 resource-limit suspension"
   ],
   "solutions": [
    "Compliance File",
    "Requirement Diff",
    "Correction Pathway"
   ],
   "processes": [
    "Deterministic Rule Check",
    "Requirement Corpus classification",
    "Attorney-bench escalation"
   ],
   "alternatives": [
    "Full-service hospital facility/corporate facility firm",
    "Spending-control prepaid card"
   ],
   "synonyms": [
    "hospital facility = FAP",
    "in-kind support and maintenance = AGB",
    "qualified community-benefit expense = QDE"
   ]
  },
  "schema_strategy": [
   {
    "type": "FAQPage",
    "where": "Homepage FAQ section and every pillar article",
    "required_fields": [
     "question",
     "acceptedAnswer"
    ],
    "caution": "Only include questions actually answered on-page; no schema for entities that don't exist yet (no reviews/ratings)"
   },
   {
    "type": "Organization",
    "where": "Homepage (deferred until owner-action facts, e.g. registered entity name, are confirmed)",
    "required_fields": [
     "name",
     "url"
    ],
    "caution": "noindex until owner-action facts close, per seo_pages.schema_status"
   }
  ],
  "internal_linking": {
   "pillar_to_cluster": "Each pillar links to its 2-3 supporting explainer pages",
   "cluster_to_pillar": "Every supporting page links back to its pillar and the homepage CTA",
   "cluster_to_cluster": "Related jurisdiction-mechanics pages cross-link once both exist",
   "service_to_location": "N/A — no location pages",
   "faq_to_commercial": "Every FAQ answer links to the Diagnostic Check CTA where relevant",
   "breadcrumbs": "Home > Compliance Engagement Mechanics > {page}",
   "anchor_text_rules": [
    "Use the exact benefits/program term as anchor text, never 'click here'"
   ]
  },
  "technical_seo": {
   "crawlability": "Single-page site at launch; sitemap added once pillar content ships",
   "indexability": "noindex until owner-action facts close (see seo_pages.noindex)",
   "sitemaps": "XML sitemap generated once pillar pages ship",
   "robots": "Disallow nothing once live; noindex meta during pre-launch",
   "canonicals": "Self-canonical on every page",
   "pagination": "N/A at this content volume",
   "faceted_nav": "N/A",
   "duplicate_control": "One URL per mechanic/topic",
   "redirects": "N/A at launch",
   "core_web_vitals": "Single self-contained HTML file keeps LCP/INP/CLS well within budget",
   "mobile": "Single-column responsive layout",
   "accessibility": "WCAG 2.2 AA per DESIGN-STANDARD §6",
   "js_seo": "Minimal JS, no client-side-only rendering of critical content",
   "rendering": "Static HTML",
   "gsc_setup": "Pending owner-action: register property post-launch",
   "analytics_setup": "Pending owner-action: attach analytics post-launch",
   "rank_tracking": "Pending owner-action: set up post-launch"
  },
  "eeat": {
   "author_bios": "Founder byline with program-expertise framing (role-title only)",
   "expert_reviewers": "[PLACEHOLDER — pending a named TEO Attorney or tax-exempt-organizations reviewer]",
   "editorial_policy": "Every factual claim cites a primary source; Verified/Inferred/Unverified labeling carried over from the blueprint",
   "fact_checking": "Cross-checked against primary 26 CFR 1.501(r)/IRS/CHNA NRC sources before publishing",
   "credentials": [
    "[PLACEHOLDER — founder credentials to be added when confirmed]"
   ],
   "citations": "Direct links/citations to IRS 26 CFR 1.501(r), IRS CHNA guidance, IRS Tax-Exempt & Government Entities division",
   "first_hand_proof": [
    "[PLACEHOLDER — first pilot-cohort determination example, anonymized, once available]"
   ],
   "update_cadence": "Re-verified each legislative session or 26 CFR 1.501(r)/state-manual release",
   "monetization_disclosure": "Pricing and guarantee stated plainly on the pricing section, no hidden monetization",
   "ymyl_notes": "Financial/compliance-adjacent content for a YMYL-sensitive audience; every claim sourced or marked [PLACEHOLDER]"
  },
  "ai_search": {
   "principles": [
    "Answer the exact buyer phrasing directly and early",
    "Cite primary sources so an assistant can attribute the answer"
   ],
   "tactics": [
    "Direct Q&A structure",
    "Named-entity consistency (always 'FacilityFile')"
   ],
   "do_not": [
    "Keyword-stuff for AI crawlers",
    "Publish unsourced statistics"
   ]
  },
  "conversion": {
   "primary_cta": "Get your free Facility Readiness Scan",
   "secondary_cta": "View the full operating blueprint dossier",
   "lead_magnets": [
    "Facility Readiness Scan",
    "501(r) Compliance Engagement Red-Flag Checklist (downloadable)"
   ],
   "trust_elements": [
    "Cited stat strip",
    "Compliance/licensing-boundary section",
    "Honest [PLACEHOLDER] proof slots"
   ],
   "per_page_paths": [
    {
     "path": "/",
     "page_type": "landing page"
    }
   ],
   "tracking": "data-event attributes (ui.*/domain.*) per DESIGN-STANDARD §4"
  },
  "link_earning": {
   "digital_pr_ideas": [
    "Aggregate, anonymized 'common compliance engagement mistake' pattern memo pitched to tax-exempt-organizations trade press"
   ],
   "original_research": [
    "Diagnostic-teardown worked-example format published as a recurring content series"
   ],
   "directories": [
    "AHA state chapter resource pages",
    "specialneedsanswers.com directory listings"
   ],
   "expert_contributions": [
    "Guest posts/webinars with AHA state chapters and multi-facility health-system networks"
   ],
   "partnerships": [
    "Settlement-planning and PI-attorney referral partners",
    "Pooled-trust nonprofit co-marketing"
   ],
   "avoid": [
    "Paid link schemes",
    "Guest posts on unrelated domains"
   ]
  },
  "roadmap_90d": [
   {
    "phase": "Phase 1",
    "goal": "Publish the AGB & CHNA mechanics hub and the flagship Facility Readiness Scan landing page",
    "pages": [
     "Homepage",
     "$50,000 resource-limit explainer",
     "AGB AGB-percentage worked example"
    ],
    "keywords_targeted": [
     "facility readiness scan hospital facility",
     "can a hospital facility pay for X"
    ],
    "required_assets": [
     "Verdict-strip diagram"
    ],
    "internal_links": [],
    "difficulty": "low",
    "business_value": "high",
    "conversion_goal": "Diagnostic Check requests",
    "why_first": "Matches the founding-pilot outreach motion already underway"
   }
  ],
  "roadmap_12m": [
   {
    "phase": "Phase 2",
    "goal": "Add a state IRS-supplement mechanics hub timed to Requirement Corpus state expansion",
    "pages": [
     "State IRS-supplement explainer",
     "TEO Attorney Determination / UPL-boundary explainer"
    ],
    "keywords_targeted": [
     "state medicaid supplement compliance engagement rules"
    ],
    "required_assets": [
     "State coverage map"
    ],
    "internal_links": [
     "/"
    ],
    "difficulty": "low",
    "business_value": "high",
    "conversion_goal": "Annual Compliance File subscription signups",
    "why_first": "Timed to the pilot cohort's actual multi-state footprint"
   }
  ],
  "priority_pages": [
   {
    "rank": 1,
    "page_title": "The $50,000 resource-limit trap: how compliance engagements can trigger it",
    "slug": "ssi-resource-limit-trap",
    "page_type": "pillar article",
    "primary_keyword": "ssi excise-tax threshold hospital facility",
    "secondary_keywords": [
     "$50,000 CHNA excise-tax threshold"
    ],
    "intent": "informational",
    "funnel": "top",
    "business_value": "high",
    "difficulty": "low",
    "conversion_potential": "medium",
    "cta": "Diagnostic Check",
    "schema": [
     "Article",
     "FAQPage"
    ],
    "internal_links": [
     "/"
    ],
    "required_proof": [
     "[PLACEHOLDER] owner to complete"
    ],
    "why_opportunity": "Thin, scattered existing coverage of the exact mechanic",
    "production_priority": "P0",
    "scope": "single article"
   }
  ],
  "competitor_gaps": {
   "typical_competitor_types": [
    "Fintech spending-control card marketing pages",
    "Nonprofit fact-sheet pages",
    "Health-law firm blog posts"
   ],
   "common_weaknesses": [
    "No worked dollar examples",
    "No citation-level rigor tied to a delivered determination"
   ],
   "how_to_beat_them": [
    "Publish citation-anchored, dated, worked-example content no incumbent produces, tied directly to a free diagnostic conversion"
   ]
  },
  "metrics": {
   "weekly": [
    "Diagnostic Check requests",
    "Organic sessions to pillar pages"
   ],
   "monthly": [
    "Check-to-pilot conversion",
    "New keyword rankings"
   ],
   "quarterly": [
    "Topical authority coverage vs. plan"
   ],
   "annual": [
    "Renewal-driven content refresh completion"
   ]
  },
  "risks": [
   {
    "risk": "YMYL content scrutiny given financial/benefits-compliance subject matter",
    "applies": true,
    "mitigation": "Every claim sourced or marked [PLACEHOLDER]; compliance disclaimers on every page"
   },
   {
    "risk": "Thin programmatic content penalty",
    "applies": false,
    "mitigation": "Programmatic generation explicitly not recommended at this stage"
   }
  ],
  "first_20_pages": [
   "Homepage",
   "$50,000 resource-limit explainer",
   "AGB AGB-percentage worked example",
   "2026 CHNA age expansion explainer"
  ],
  "first_10_tech_fixes": [
   "Confirm noindex removed only after owner-action facts close",
   "Add XML sitemap once pillar pages ship"
  ],
  "first_10_authority_actions": [
   "Publish the 10-post educational content series",
   "Open AHA state-chapter webinar co-marketing conversations",
   "Publish the 501(r) Compliance Engagement Red-Flag Checklist lead magnet"
  ],
  "final_recommendation": "Launch the homepage and the AGB & CHNA mechanics hub together; hold multi-state content for the timed Requirement Corpus expansion; keep every claim citation-anchored given the YMYL sensitivity of financial/benefits-compliance content for facilities.",
  "disclaimers": [
   "This SEO plan is operational guidance, not legal or tax advice.",
   "All cited figures must be re-verified against primary sources before publishing.",
   "No fabricated reviews, ratings, or case results — proof content ships only as real pilot outcomes exist."
  ]
 },
 "microsite": {
  "category": "IRC §501(r) financial-assistance & community-benefit compliance for nonprofit hospitals",
  "shortTitle": "FacilityFile 501(r) Compliance Desk",
  "audience": "CFOs, VPs Finance, Compliance Officers, and Tax Directors of standalone/rural nonprofit community hospitals and mid-size nonprofit health systems (5-20 facilities), no in-house tax-exempt counsel",
  "problem": "Every nonprofit hospital facility must independently satisfy six §501(r) requirements (CHNA, FAP, EMCP, AGB, billing/collection, Schedule H reporting) — miss the CHNA and it's a $50,000 excise tax per facility, per year; miss enough of the rest and the facility's income is taxed and the exemption can be revoked. Most standalone hospitals have no in-house tax-exempt counsel and rebuild the FAP or CHNA from a stale prior-year template each cycle.",
  "offer": "Free Facility Readiness Scan -> §501(r) Facility Compliance Audit & Correction File ($14,000-$28,000 one-time, per facility) + Annual Compliance File subscription ($12,000-$24,000/yr) -> optional Triennial CHNA + Implementation Strategy Package ($22,000-$45,000/cycle) -> optional Remediation & Defense ($18,000-$60,000/matter) -> optional System Portfolio bundle (25-40% volume discount, 5+ facilities).",
  "faq": [
   {
    "q": "Do you replace our attorney or our auditor?",
    "a": "No. FacilityFile does not provide legal advice, does not represent itself as a law firm, and does not perform an independent financial-statement audit. We produce the Compliance File from the policies and remittance data you supply; your own counsel and auditor remain the right parties for legal review and financial-statement assurance."
   },
   {
    "q": "Who actually signs the compliance determination?",
    "a": "An independently engaged tax-exempt-organizations (TEO) attorney. Neither AI nor FacilityFile staff may review or sign the compliance determination or any correction-and-disclosure strategy."
   },
   {
    "q": "Who signs the AGB calculation and Schedule H representation?",
    "a": "An independently engaged healthcare CPA. The Healthcare CPA reviews the AGB Workpaper's tie-out and signs both the AGB calculation and the Schedule H representation your facility relies on for its Form 990."
   },
   {
    "q": "Do you help individual patients with a bill or a financial-assistance application?",
    "a": "No, never. FacilityFile's client is the hospital facility itself, not any individual patient. We do not advise patients, do not determine individual financial-assistance eligibility, and do not collect consumer or personal debt under any circumstance."
   },
   {
    "q": "What if the IRS still finds a gap in a delivered file?",
    "a": "No compliance service can guarantee an agency's future finding, and we do not claim to. Every Compliance File is dated to the requirement-corpus version and the facts submitted, with a full evidence log — the actual evidence of due diligence a board or examiner needs."
   }
  ],
  "process": [
   {
    "title": "Intake & normalize",
    "body": "Upload your current FAP/EMCP/billing policy, prior CHNA, most recent Schedule H, and 12 months of remittance data; every field is checked against the intake completeness checklist."
   },
   {
    "title": "Requirement Diff",
    "body": "Each of the six §501(r) requirements is scored against the current 26 CFR 1.501(r) checklist, with a CFR citation on every finding."
   },
   {
    "title": "Draft and approve",
    "body": "AI drafts the corrected FAP/EMCP, AGB Workpaper, and Schedule H Narrative; a Compliance Analyst approves completeness before anything reaches a licensed signer."
   },
   {
    "title": "Dual sign-off",
    "body": "A TEO Attorney signs the compliance determination; a Healthcare CPA signs the AGB Workpaper and Schedule H representation."
   },
   {
    "title": "Deliver & renew",
    "body": "The signed Compliance File is delivered, and CHNA clocks and AGB recalculation dates are tracked ahead of your next cycle."
   }
  ],
  "northStarCta": {
   "label": "Get my free Facility Readiness Scan",
   "href": "#start",
   "secondary_label": "See the six requirements",
   "secondary_href": "#requirements"
  },
  "trust": {
   "standards": [
    "Done-for-you compliance-file production — not a law firm, and not a substitute for your engaged TEO Attorney or Healthcare CPA",
    "FacilityFile's client is always the Facility (the institutional tax-exempt organization); individual patients are never served or advised",
    "A human Compliance Analyst reviews every artifact; a TEO Attorney and a Healthcare CPA sign every Compliance File"
   ],
   "response_time": "Facility Readiness Scan returned within 3 business days of a request",
   "data_handling": "Signed DPA/BAA per Facility, least-privilege access, retention limits, remittance data de-identified to minimum-necessary"
  },
  "hook": "Your facility's CHNA clock doesn't move, and no one on staff is tax-exempt counsel.",
  "sub_headline": "Send your current FAP/EMCP, prior CHNA, and remittance data. Get a filed-ready, dual-signed §501(r) Compliance File — flat fee per facility, 3-4 weeks at launch.",
  "dream_outcome": "A complete, defensible, examiner-ready Compliance File and a TEO Attorney's signed determination in your board's hands — without hiring tax-exempt counsel onto your own small staff.",
  "specific_pains": [
   "No one on staff has tax-exempt-law training, so the board's exposure question goes unanswered until an IRS letter forces it.",
   "The FAP and CHNA get rebuilt from a stale prior-year template instead of current policy and remittance data.",
   "A multi-facility system must track a completely different CHNA clock and AGB recalculation date in every facility it operates.",
   "A live 2025 IRS examination wave and Congressional scrutiny of the nonprofit-hospital exemption raise the cost of getting this wrong."
  ],
  "cost_of_inaction": "The IRS has already revoked at least one hospital's exemption over a §501(r)/community-benefit failure, and a missed CHNA is a $50,000 excise tax per facility, per year — before any broader exemption risk.",
  "mechanism": {
   "name": "The Facility Compliance Cycle",
   "steps": [
    {
     "title": "Intake",
     "body": "Current policies, prior CHNA, Schedule H, and remittance data confirmed complete before review begins."
    },
    {
     "title": "Classify",
     "body": "Deterministic requirement gates (CHNA clock, AGB recalculation trigger, LEP language threshold) run first; the AI engine classifies against the current requirement corpus and drafts a finding with citations."
    },
    {
     "title": "Review",
     "body": "A Compliance Analyst reviews every draft — confirms, corrects, and checks Exception Queue escalation criteria."
    },
    {
     "title": "Sign",
     "body": "The TEO Attorney signs the compliance determination; the Healthcare CPA signs the AGB Workpaper and Schedule H representation."
    },
    {
     "title": "Deliver",
     "body": "The signed Compliance File ships with full citations, requirement-corpus version, and a scope-of-engagement disclaimer, logged to the evidence list."
    }
   ]
  },
  "offer_stack": [
   {
    "item": "Compliance File",
    "note": "dated, cited, examiner-ready — corrected FAP/EMCP, AGB Workpaper, Schedule H Narrative"
   },
   {
    "item": "Requirement Diff",
    "note": "the specific requirement-by-requirement gap read with CFR citations"
   },
   {
    "item": "CHNA Package",
    "note": "triennial Community Health Needs Assessment + board-adoptable implementation strategy"
   },
   {
    "item": "Remediation & Defense",
    "note": "TEO Attorney-led correction-and-disclosure strategy for a facility behind or under exam"
   },
   {
    "item": "System Portfolio Review",
    "note": "full-portfolio CHNA-clock drift check for System Portfolio subscribers"
   }
  ],
  "guarantee": "If a delivered Compliance File is incomplete or rejected for a FacilityFile-caused error, the correction is not re-billed for that cycle. Not a guarantee of any specific IRS examination outcome.",
  "urgency": "The founding-pilot cohort is hard-capped at 5 hospital facilities at launch pricing — not artificial scarcity, an operational limit while the requirement corpus and TEO Attorney/Healthcare CPA bench are proven.",
  "objections": [
   {
    "q": "Our health-law firm already handles this.",
    "a": "At a point-in-time review, yes — not as a continuously-maintained file across all six requirements, updated every year, at a flat per-facility rate instead of professional-services hourly billing."
   },
   {
    "q": "We can't afford another vendor.",
    "a": "$14,000-$28,000 one-time for the Facility Compliance Audit, well under a full law-firm-plus-consultant scramble or a $50,000/yr CHNA excise. The free Facility Readiness Scan shows you the gap read on your own facility before you spend anything."
   },
   {
    "q": "Is this even allowed — are you practicing law?",
    "a": "No. FacilityFile delivers AI-assisted compliance research to you as the facility's institutional customer of record, not legal advice. The compliance determination is signed only by an independently engaged TEO Attorney."
   },
   {
    "q": "What if we're managing a dozen facilities across several states?",
    "a": "That's exactly the System Portfolio profile — the requirement corpus expands state by state as pilot facilities onboard, with a 25-40% volume discount."
   }
  ],
  "who_this_is_not_for": [
   "An individual patient or family managing a personal billing dispute or financial-assistance application — FacilityFile serves the hospital's institutional compliance function only and refers individual questions to the facility's own posted FAP contact",
   "Anyone wanting FacilityFile to file the Form 990 as return preparer, act as legal counsel, or serve as the facility's compliance officer of record (this is a B2B compliance-production service, not a staffing replacement)",
   "A facility already the subject of active litigation over a §501(r) matter — that stays with the facility's own counsel",
   "Large health systems that already have in-house tax-exempt counsel and a healthcare CPA performing this exact function on staff"
  ],
  "proof_pillars": [
   {
    "title": "Cited, not claimed",
    "body": "Every stat on this page cites a named, dated source (IRS guidance, Ways & Means testimony, a named law-firm alert) — never an invented statistic."
   },
   {
    "title": "Dual-signed, always",
    "body": "No Compliance File ever ships without a named TEO Attorney's and Healthcare CPA's sign-off."
   },
   {
    "title": "Honest about what's new",
    "body": "This is a new practice entering its pilot cohort — real results will appear here as facilities complete a cycle, not before."
   }
  ],
  "stakes_line": "Every filing cycle a facility completes without a dual-signed compliance check is a decision the board is personally exposed on if it turns out wrong — and most facilities only find out after an IRS exam letter arrives.",
  "deliverable": "A dated, cited Compliance File, a Requirement Diff with CFR citations, a CHNA Package where engaged, a TEO Attorney determination, a Healthcare CPA sign-off, and a full evidence list retained for the engagement's defined period.",
  "unit_of_work": "one Facility, one filing cycle — the annual Compliance File or the triennial CHNA Package",
  "lexicon": {
   "regulator": "IRS",
   "regulator_full": "Internal Revenue Service, Tax-Exempt & Government Entities division, applying IRC §501(r) and 26 CFR 1.501(r)-1 through -7, plus applicable state charity-care overlays",
   "statute": "IRC §501(r); 26 CFR 1.501(r)-1 through -7; IRC §4959",
   "statute_frame": "cited by CFR subsection or code section, e.g. '26 CFR 1.501(r)-5' or 'IRC §4959'",
   "persona": "CFO / Compliance Officer / Tax Director",
   "persona_moment": "an IRS exam letter, an upcoming CHNA deadline, or a board question about exposure lands on the CFO's desk",
   "trigger_moment": "a facility's current filing cycle is due",
   "enforcement_stakes": "a $50,000 excise tax per facility per year, taxation of the facility's income, or outright revocation of §501(c)(3) status — no appeal reverses a lapsed exemption year",
   "retention": "renewal driven by the Annual Compliance File subscription and the evidence-log lock-in as a health system's facility roster grows",
   "cta_verb": "Get your free Scan",
   "intake_checklist": [
    "Current FAP, EMCP, and billing-and-collection policy",
    "Prior CHNA and Implementation Strategy, if any",
    "Most recent Form 990 Schedule H",
    "12 months of allowed-claims (835 remittance) data",
    "Facility roster and state(s) of operation"
   ],
   "regulator_faqs": [
    {
     "q": "Does FacilityFile ever act as our facility's IRS point of contact?",
     "a": "No — FacilityFile never files on the facility's behalf and never communicates with the IRS as the facility's representative. We work from facility-authorized facts and documents only, and prepare (not file or sign) every artifact."
    },
    {
     "q": "What happens if the IRS later questions a delivered file?",
     "a": "The Compliance Analyst and, where relevant, the TEO Attorney support the facility with the full evidence list; if it escalates toward a formal examination response, we hand the facility's counsel a complete, cited file and step back from legal advocacy."
    }
   ],
   "trust_standards_specific": [
    "[PLACEHOLDER] owner to complete"
   ]
  },
  "proof_angle": {
   "id": "diagnostic-teardown",
   "headline": "A public-FAP teardown found a missing LEP-language threshold before an examiner did",
   "lever": "Anonymized diagnostic teardown",
   "outcome_verb": "quantified",
   "outcome_frame": "Requirement Diff with the exact CFR citation and a Correction Pathway",
   "proof_promise": "Every citation in your own Compliance File traces to your own facility's facts and the current requirement corpus — no aggregate industry statistic stands in for your facility's actual posture."
  },
  "indexable": false,
  "ubiquitousLanguage": {
   "audience": "CFO / Compliance Officer / Tax Director",
   "domain": "IRC §501(r) hospital community-benefit & financial-assistance compliance",
   "deliverable": "Compliance File",
   "reviewer": "Compliance Analyst",
   "record": "Facility",
   "unit_of_work": "Facility filing cycle",
   "cta_primary": "Get my free Facility Readiness Scan",
   "cta_secondary": "View the full operating blueprint dossier",
   "regulator": "IRS",
   "regulator_full": "Internal Revenue Service, Tax-Exempt & Government Entities division",
   "statute": "IRC §501(r); 26 CFR 1.501(r)-1 through -7",
   "trigger_moment": "a facility's current CHNA, FAP, or AGB filing cycle is due, or an IRS exam letter arrives",
   "event_intake_started": "domain.diagnostic_requested",
   "event_conversation_requested": "ui.cta_primary"
  }
 },
 "evidence": [
  {
   "id": "501r-community-benefit-compliance-engine-ev1",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "regulatory",
   "claim_or_finding": "A CHNA/implementation-strategy failure triggers a $50,000 excise tax per noncompliant facility, per year, under IRC §4959; broader failure risks revocation of §501(c)(3) status",
   "status": "verified",
   "evidence": "IRS 'Consequence of Non-Compliance with Section 501(r)' guidance page; CRS R48027 (source blueprint [S6][S7])",
   "verification_command": "Not independently re-fetched this run — no live web access in this session",
   "fix_owner": "content",
   "remediation": "Re-verify live before public launch; inherited Verified label from source blueprint unchanged",
   "severity": "info"
  },
  {
   "id": "501r-community-benefit-compliance-engine-ev2",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "regulatory",
   "claim_or_finding": "The IRS opened a hospital examination wave; roughly 35 organizations were under active §501(r) examination by late 2024, on top of the statutory triennial community-benefit review",
   "status": "verified",
   "evidence": "Potomac Law and Krieg DeVault 2024-25 alerts; PL 111-148 §9007(c); IRS TE/GE (source blueprint [S9][S13][S19])",
   "verification_command": "Not independently re-fetched this run",
   "fix_owner": "content",
   "remediation": "Re-verify live before public launch",
   "severity": "info"
  },
  {
   "id": "501r-community-benefit-compliance-engine-ev3",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "market",
   "claim_or_finding": "Roughly 2,900 nonprofit 501(c)(3) community hospitals operate in the U.S.",
   "status": "inferred",
   "evidence": "AHA; Community Benefit Insight (source blueprint [S10][S21]) — exact count varies by definition",
   "verification_command": "Not independently re-fetched this run",
   "fix_owner": "content",
   "remediation": "Directional sizing only; do not present as a precise count in client-facing material",
   "severity": "low"
  },
  {
   "id": "501r-community-benefit-compliance-engine-ev4",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "regulatory",
   "claim_or_finding": "A September 2025 House Ways & Means hearing and bipartisan Senate probes questioned the ~$37.4B annual value of the nonprofit-hospital tax exemption; research cited finds ~80% of tax-exempt hospitals spend less on community benefit than the value of their tax break",
   "status": "verified",
   "evidence": "Ways & Means / Whaley testimony, Sept 2025; Senator Grassley press release (source blueprint [S11][S12][S23])",
   "verification_command": "Not independently re-fetched this run",
   "fix_owner": "content",
   "remediation": "Re-verify live before public launch",
   "severity": "info"
  },
  {
   "id": "501r-community-benefit-compliance-engine-ev5",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "pricing",
   "claim_or_finding": "CHNA consultancies, healthcare CPA advisory lines, and health-law firms each sell a fragment of §501(r) compliance work at professional-services rates; no incumbent found delivers a single continuously-maintained, signed file across all six requirements",
   "status": "inferred",
   "evidence": "Market scan of named vendors (Crescendo, PRC, RMS, Baker Tilly, CLA, Forvis Mazars, Nixon Peabody, Krieg DeVault) per source blueprint [S8][S18][S19]",
   "verification_command": "Not an exhaustive vendor search; not independently re-fetched this run",
   "fix_owner": "content",
   "remediation": "Re-verify before a specific competitive claim is made publicly",
   "severity": "low"
  },
  {
   "id": "501r-community-benefit-compliance-engine-ev6",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "regulatory",
   "claim_or_finding": "Roughly 20 states now mandate their own minimum free/discounted charity-care income limits, layered on top of the federal §501(r) baseline; Oregon adds a minimum community-benefit-spending requirement",
   "status": "verified",
   "evidence": "Nixon Peabody; American Bar Association Health Law (source blueprint [S16][S17])",
   "verification_command": "Not independently re-fetched this run",
   "fix_owner": "content",
   "remediation": "Re-verify current state count and specifics before citing a specific state's statute in a live engagement",
   "severity": "medium"
  },
  {
   "id": "501r-community-benefit-compliance-engine-ev7",
   "business_slug": "501r-community-benefit-compliance-engine",
   "area": "pain",
   "claim_or_finding": "The AGB percentage must be recalculated at least annually from allowed-claims data, with the FAP updated whenever the AGB method changes",
   "status": "verified",
   "evidence": "26 CFR 1.501(r)-5; IRS §501(r)(5) guidance (source blueprint [S4][S22])",
   "verification_command": "Not independently re-fetched this run",
   "fix_owner": "content",
   "remediation": "n/a — inherited Verified label from source blueprint unchanged",
   "severity": "info"
  }
 ],
 "seo_pages": {
  "id": "seo-501r-community-benefit-compliance-engine",
  "business_slug": "501r-community-benefit-compliance-engine",
  "route": "/501r-community-benefit-compliance-engine",
  "title": "FacilityFile — 501(r) compliance file production for nonprofit hospitals",
  "description": "FacilityFile for nonprofit hospital facilities managing IRC §501(r) compliance. A dated, cited, dual-signed Compliance File — priced per facility, never hourly, starting with a free Facility Readiness Scan.",
  "canonical": "/501r-community-benefit-compliance-engine",
  "og_title": "FacilityFile — 501(r) Compliance File for Nonprofit Hospitals",
  "og_description": "FacilityFile for nonprofit hospital facilities managing IRC §501(r) compliance. A dated, cited, dual-signed Compliance File — priced per facility, never hourly.",
  "schema_type": "Service",
  "schema_status": "Service + Organization schema only; no FAQPage rich-result schema used (Google retired FAQ rich results; plain FAQ text on the page instead)",
  "sitemap_include": false,
  "noindex": true
 },
 "vertical_style": {
  "accent": "copper-forest",
  "signature": "Requirement-ladder strip with a CFR citation chip beneath the active finding",
  "layout": "501(r) compliance desk index",
  "anti": "Fintech alarm-red urgency banners, stock hospital-exterior imagery, and generic SaaS gradient heroes"
 },
 "canva": {
  "slug": "501r-community-benefit-compliance-engine",
  "territory": "forest-copper",
  "family": {
   "id": "ledger-guardian-v1",
   "name": "Ledger Guardian",
   "motion": "minimal, functional only"
  },
  "tokens": {
   "brand": "222 46% 24%",
   "brand-fg": "0 0% 100%",
   "surface": "45 22% 96%",
   "ink": "222 32% 12%",
   "muted": "222 12% 36%",
   "accent": "36 82% 32%"
  },
  "type": {
   "display": "system-ui, 'Georgia', serif fallback for headings",
   "body": "system-ui, -apple-system, 'Segoe UI', sans-serif",
   "fonts_url": "none — system font stack only, no external font requests"
  },
  "scale": {
   "h1": "40px/1.16",
   "h2": "28px/1.2",
   "h3": "20px/1.3",
   "body": "16px/1.6",
   "small": "13px/1.5",
   "tracking_display": "-0.01em",
   "tracking_body": "0",
   "weight_display": 600,
   "weight_body": 400
  },
  "spacing": {
   "card_padding": "20px",
   "card_radius": "8px",
   "card_shadow": "0 1px 2px rgba(21,20,15,0.08)",
   "section_gap": "56px",
   "hero_gap": "24px"
  },
  "layout": {
   "hero": "left-aligned copy, right-aligned verdict-strip visual",
   "card": "bordered, low-shadow, ledger-style",
   "cta": "solid accent button, high contrast text",
   "archetype": "compliance determination desk",
   "card_silhouette": "rectangular with an 8px radius, thin border, no heavy shadow",
   "button_geometry": "rectangular with a 6px radius, no pill shapes"
  },
  "background": {
   "hero_gradient": "none — flat brand surface with a subtle radial tint",
   "cta_gradient": "none — flat accent surface",
   "section_wash": "alternating surface / surface-raised bands"
  },
  "motif": "Four-badge requirement ladder: CHNA -> FAP/EMCP -> AGB -> Billing & Collection"
 },
 "capabilities": {
  "marketing": true,
  "portal": false,
  "ops": true,
  "chatbot": false,
  "payments": false
 },
 "generated_at": "2026-07-18T05:24:18Z",
 "ddd_coverage": {
  "slug": "501r-community-benefit-compliance-engine",
  "total": 17,
  "passed": 17,
  "pct": 100,
  "checks": [
   {
    "key": "subdomains",
    "label": "Subdomains identified",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "bounded_contexts",
    "label": "Bounded contexts defined",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "aggregates",
    "label": "Aggregates named",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "domain_events",
    "label": "Domain events named",
    "count": 6,
    "min": 4,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "commands",
    "label": "Commands named",
    "count": 6,
    "min": 4,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "policies",
    "label": "Policies defined",
    "count": 4,
    "min": 2,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "ai_agents",
    "label": "AI agents specified",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "ai-governance",
    "unblock": "n/a"
   },
   {
    "key": "invariants",
    "label": "Invariants enforced",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "risk_register",
    "label": "Risk register entries",
    "count": 3,
    "min": 3,
    "ok": true,
    "gate": "risk",
    "unblock": "n/a"
   },
   {
    "key": "adrs",
    "label": "ADRs recorded",
    "count": 2,
    "min": 1,
    "ok": true,
    "gate": "architecture",
    "unblock": "n/a"
   },
   {
    "key": "use_cases",
    "label": "Use cases documented",
    "count": 2,
    "min": 2,
    "ok": true,
    "gate": "domain-modeling",
    "unblock": "n/a"
   },
   {
    "key": "human_roles",
    "label": "Human roles defined",
    "count": 3,
    "min": 2,
    "ok": true,
    "gate": "ai-governance",
    "unblock": "n/a"
   },
   {
    "key": "human_review_checkpoints",
    "label": "Human review checkpoints",
    "count": 4,
    "min": 2,
    "ok": true,
    "gate": "ai-governance",
    "unblock": "n/a"
   },
   {
    "key": "data_objects",
    "label": "Data objects owned",
    "count": 3,
    "min": 2,
    "ok": true,
    "gate": "data",
    "unblock": "n/a"
   },
   {
    "key": "external_integrations",
    "label": "External integrations mapped",
    "count": 4,
    "min": 2,
    "ok": true,
    "gate": "architecture",
    "unblock": "n/a"
   },
   {
    "key": "security_controls",
    "label": "Security controls specified",
    "count": 3,
    "min": 2,
    "ok": true,
    "gate": "security",
    "unblock": "n/a"
   },
   {
    "key": "mvp_roadmap",
    "label": "MVP roadmap phases",
    "count": 1,
    "min": 1,
    "ok": true,
    "gate": "roadmap",
    "unblock": "n/a"
   }
  ],
  "failingGates": []
 },
 "checksum": "69c4ad2ff72a2d07"
}