You build the pipeline. Not a ticket to engineering.
The person who knows the process wires the process — and can change it on a Tuesday afternoon without waiting on a release.
39modules
$0per test run
14dobserve before acting
Frozenpublished versions
surethink.app/pipelines/surety-intake v14 · published · immutable
Triggers
email_watch
api_intake
folder_watch
schedule
Intelligence
doc_classifier
wip_extractor
ratio_analyst
Gates
rule_pack_gate
confidence_gate
Human
approval_tray
four_eyes
Output
letter_writer
record_write
email_watchi0 · submissions@
doc_classifieri1 · 12 types
wip_extractori2 · graded fields
ratio_analysti3 · 9 ratios
rule_pack_gatei4 · 77 rules
approval_trayi5 · parks here
record_writei7 · hash-chained
Gate
Rule pack
i4 · rule_pack_gate
Rules in force
contract surety v1pin a version
Hand to a person when a field is
readderivedinferredabsent
Route to
senior approval tray
Controls
Four-eyes above $1M
Observe mode
Daily AI budget $50
The gate that decides whether a file goes on or stops is one panel with four settings. That is deliberate — the moment a control needs a consultant, it stops being a control your team actually owns.
The catalog
39 modules. Not a curated six.
Here is the whole thing, because the interesting question is never what a demo shows — it is whether the module you need is in there.
■ triggers■ intelligence & gates■ human stations■ output
Before it touches a live file
Three ways to be sure before you’re committed.
01 · Test Bench
Dry-run it for nothing
Point the pipeline at pinned fixtures — real files you have already decided — and watch what it would have done. No AI spend, no live data, no consequences.
run 41 fixtures 38 match prior decision 3 differ — review cost $0.00
02 · Observe mode
Let a new rule watch first
A rule in observe mode reports what it would have done, on live files, without being allowed to act. Turn it loose only once its record convinces you.
CS-091 · observing 14d would refer 6 of 212 0 false stops ready to enforce
03 · Frozen versions
Publishing locks it
A published version cannot be edited, only superseded. A case decided in March replays under March’s logic — which is the only way a replay means anything.
v14 live since 8 Sep v13 · 212 cases pinned replay exact
v14Added confidence_gate before the rule pack; inferred fields now route to the senior traylive · 8 Sep 2026
v13Raised the four-eyes threshold from $750k to $1M after the Q2 authority review212 cases pinned
v12Added folder_watch for the broker drop; exclusion screen moved ahead of extraction88 cases pinned
v11First published version — email intake, classifier, extractor, rule pack, approval tray341 cases pinned
Every version keeps the cases decided under it. Nothing is migrated onto new logic, because a decision made under old rules was made under old rules.
What it costs to run
Metered per call, capped per day.
Every model call a pipeline makes is timed, counted and priced at the moment it happens, against a rate card with effective dates. Spend is a number you watch, not a bill you receive.
Control
What it does
Where
daily_budget
A ceiling per pipeline per day. When it is reached the pipeline holds rather than overspending, and the queue says why.
per pipeline
per_call_meter
Tokens in, tokens out, duration and outcome recorded on success and on failure — a call that errored still cost money and still shows up.
every call
priced_at_write
Cost is frozen when the call happens. A later change to the rate card never rewrites history.
every call
unpriced_model
A model with no rate card entry reports as unknown cost, never as zero. You find out by seeing a gap, not by being quietly wrong.
every call
Test Bench runs are excluded from all of this, because they never call a model.
Start with one workflow
We’ll wire your process while you watch.
Thirty minutes. Bring one real file, redacted however you need it, and we'll build the pipeline that would have handled it — then run it in the Test Bench for nothing.