Production
TM

Good morning, Timothy

Six crews in production across four workspaces. Two items need a decision from you today.

Runs today
215
+12% vs 7-day mean
Awaiting you
2
Oldest waiting 41 min
Credits today
11,878
S$118.78 · 48% of daily budget
Review rate
23%
down from 100% at launch
Open incidents
1
Provider latency, degraded

Active runs

RunCrewStageStateCreditsCost
RUN-8F2C41LawCrew Document ReviewAdversarial review · 7/11Running218S$2.18
RUN-8F2B90Content StudioSenior editor gateAwaiting approval142S$1.42
RUN-8F2951Finance CloseReconciliation · evidence below floorAbstained330S$3.30
RUN-8F29E3AML Screening AdvisorySanctions gate · escalatedEscalated87S$0.87
RUN-8F2A17BizDev IntelligenceCompleted · 14 opportunitiesComplete405S$4.05
RUN-8F28C4Matter Intake TriageConnector timeout at node 4Failed64S$0.64
RUN-8F2D07Content StudioParked at checkpoint · node 5/9Awaiting credit96S$0.96

Your decisions

SLA
Professional sign-off
LawCrew · dual approval · 41 min
Overdue
PUB
Publication approval
Content Studio · bilingual article
2h left

Attention

ABS
Abstentions · evidence gap
Finance Close abstained 3× on FX revaluation
SRC
Source expired
MAS Circular pack · 14 artefacts affected
CRD
Run parked · awaiting credit
Content Studio · resumes automatically on top-up · 68h of 72h left
AUT
Autonomy graduation ready
AML Screening eligible for extended sampling

Crew health

Content Studio v4.2.0
Extended sampling · 15%
96.2%
AML Screening Advisory v2.7.1
Supervised sampling · 10%
97.1%
LawCrew Review v3.0.2
Regulated floor · 100%
91.4%
BizDev Intelligence v1.9.4
Supervised sampling · 25%
94.8%

Recommended for you

PK
SG Tender Response Pack
Maintained Pack · 6 templates · updated 2d ago
PD
Source & Citation Verification Pod
Used by 4 of your crews
AG
Freshness Checker
Would have caught your expired MAS source

Platform notices

New model profile writing-premium-v3 available. Migration comparison ready in Evaluation Lab.
Provider latency elevated on research-standard. Fallback chain engaged for 6 runs.
Knowledge source mas-circulars passed its freshness window 2 days ago.

KrewOS Hub

Classified, versioned and evaluated components. Start from something proven rather than an empty canvas.

Filters

Industry
Legal services Financial servicesAquacultureeCommerce
Jurisdiction
Singapore MalaysiaASEANGlobal
Risk level
InformationalOperational Regulated
Human control
No approvalOptionalMandatoryDual
Quality status
wGrow verified Tenant verifiedTestedDraft
Language
English中文BahasaBilingual

Maintained Packs

Subscription
SG
Singapore Legal Practice Pack
4 crew templates · 19 agents · statutes tracked weekly · current as of 13 Aug 2026
Licensedv6.3.0
FS
MAS Financial Compliance Pack
3 crew templates · 14 agents · circulars tracked daily · 1 source stale
Licensedv4.1.2
AQ
Aquaculture Operations Pack
2 crew templates · 11 agents · water chemistry references
Availablev2.0.0
TD
SG Tender Response Pack
6 crew templates · GeBIZ connector · updated 2 days ago
Availablev1.4.0

Components

Sorted by reuse
ComponentLevelClassificationStatusUsed byVersion
Evidence Researcher
Plans searches, retrieves and cites sources
AgentResearch · Cross-industry wGrow verified31 crews5.2.1
Source Verifier
Confirms authority, freshness and quotation accuracy
AgentReview · Cross-industry wGrow verified28 crews4.0.3
Evidence Research Pod
Search planner + researcher + verifier + citation checker
PodResearch · Cross-industry wGrow verified22 crews3.2.0
Adversarial Reviewer
Challenges claims before release
AgentReview · Regulated wGrow verified17 crews2.8.0
SG Jurisdiction Router
Routes by governing law and forum
AgentRouting · Singapore law Tenant verified6 crews1.6.2
Regulatory Review Pod
Compliance checks with deterministic gates
PodCompliance · Regulated wGrow verified9 crews2.4.1
LawCrew Document Review
Jurisdiction routing → drafting → adversarial review → sign-off
TemplateLegal · Singapore · Regulated wGrow verified3 tenants3.0.2
Memory Curator
Gates promotion into long-term memory
AgentOperations · Cross-industry Tested11 crews1.2.0
PodwGrow verifiedpod://evidence-research@3.2.0

Evidence Research Pod

Plans a search strategy, retrieves from authorised knowledge, verifies source authority and freshness, and returns cited Evidence with a sufficiency score.

Evaluation
94.2% pass
Median cost
42 cr · S$0.42 per invocation
Median latency
18.4s
Reuse
22 crews · 4 tenants
Support
Maintained
Input schema
ResearchBrief · schemas/ResearchBrief.schema.json
  question        string, required
  jurisdiction    enum[SG,MY,ID,ASEAN,GLOBAL]
  languages       array<string>, default [en]
  authority_floor enum[any,secondary,primary], default primary
  max_sources     integer, default 12
Output schema
EvidenceSet · schemas/EvidenceSet.schema.json
  findings[]      claim, support[], confidence
  evidence[]      source_id, excerpt, authority_tier, retrieved_at, url
  sufficiency     Sufficiency Score 0–1 · abstention below the evidence floor
  conflicts[]     sources that disagree, with both positions
  gaps[]          what could not be established, and why
Effect Declaration
reads:knowledge reads:web(allowlist) writes:none side-effects:none spend:≤S$1.50/call
The Effect Declaration is compiler-checked. A crew placing this Pod downstream of untrusted input cannot connect it to any node declaring side-effects:external without an approval gate between them.

Internal composition

NodeComponentModel profileEffects
planSearch Planner 2.1.0classify-fastreads:none
retrieveEvidence Researcher 5.2.1research-standardreads:knowledge, web
verifySource Verifier 4.0.3research-standardreads:knowledge
citeCitation Checker 3.3.0deterministicnone
freshFreshness Checker 1.8.1deterministicreads:metadata

Requirements

Model capability
Long context, tool use
Knowledge Packs
1 or more
Tools
Retrieval, web (allowlist)
Human roles
None required
Manifest schema
≥ 2.0
Risk level
Informational
Licence
wGrow internal

Known limitations

Chinese-language primary sources retrieve at lower recall than English. Pair with Translation Agent for zh corpora.
Sufficiency scoring is calibrated on legal and financial corpora. Recalibrate before use in clinical domains.
Web retrieval is allowlist-only by design; broad open-web research needs a forked variant with tenant approval.

Dependents

Impact on change
LawCrew Document Review
Regression suite required
Regulated
Content Studio
Regression suite required
Operational
BizDev Intelligence
Regression suite required
Operational
+ 19 more crews
3 tenants outside wGrow

New project

Describe the outcome you need. KrewOS infers the classification, recommends a template, and tells you what is still missing.

Step 1 · What should this crew produce?

Complete
“We receive commercial tenancy agreements from clients and need a first-pass review that flags unusual clauses against Singapore law, drafts suggested amendments with authority, and produces a memo a partner can sign off. Everything must be traceable and a qualified lawyer must approve before it leaves.”
Inferred classification
Industry Legal services Function Review, drafting Jurisdiction Singapore Language English Risk Regulated Input PDF, DOCX Output Memo, redline Human Mandatory specialist

Step 2 · Recommended templates

3 matches
92
LawCrew Document Review v3.0.2
Jurisdiction routing · drafting · adversarial review · deterministic risk checks · professional approval
Covers all inferred requirements. Needs your firm's clause library and an approver group.
71
Contract Clause Extraction Crew v2.1.0
Extraction and comparison only. No drafting, no professional approval gate.
64
Regulatory Review Pod v2.4.1
A component rather than a full crew. Use if you are assembling your own workflow.

Step 3 · Configure

4 items outstanding
SettingValueSourceState
Output languageEnglishFrom your descriptionSet
Governing lawSingaporeFrom your descriptionSet
Model policycapability-basedTenant defaultSet
Clause libraryNot connectedKnowledge Pack requiredNeeded
Approver groupNot assignedMandatory for regulated riskNeeded
Budget per runNot setTenant ceiling S$12.00Needed
Credit reservation478 cr per runComputed, not configured · P90 × 1.15, floor 8Automatic
Document intakeNot connectedConnector or manual uploadNeeded

What you will get

Agents
9
Pods
3
Human gates
2
Deterministic checks
6
Evaluation cases
84 inherited
Est. cost per matter
210 – 440 cr · S$2.10 – S$4.40
Est. duration
6 – 14 min
Initial review rate
100%

Governance preview

This template is classified regulated. It launches at Full review and cannot graduate to Supervised sampling until 200 reviewed outcomes are recorded.
Dual approval is required before any external Action. No publishing or sending Action is configured in this template.

Next

crew://lawcrew-document-review@3.1.0-draftDraft · unvalidated changes

LawCrew Document Review

Assemble mode. The canvas is an editor — the manifest is the source of truth, and every change here resolves into a versioned diff.

Validation
2 blocking
Effect check
Passed
Est. cost / run
210 – 440 cr · S$2.10 – 4.40
Evaluation
Stale · rerun needed
Base release
v3.0.2
IntakeDET
PDF · DOCX
Jurisdiction RouterAGT
classify-fast
Evidence ResearchPOD
pod@3.2.0 · 5 nodes
Clause DrafterAGT
writing-premium
Adversarial ReviewerAGT
writing-premium
Risk ChecksDET
6 rules · policy@1.8
Partner Sign-offHUM
dual approval
Return to ClientACT
idempotent · n8n
Evidence Gap QueueABS
abstention · sufficiency < 0.72
11 nodes3 pods2 human gates1 action

Validation

2 blocking · 2 advisory
!
Revision loop has no maximum iteration
adversarial-reviewer → clause-drafter · FR-WFL-005
!
Approver group unassigned
partner-signoff · mandatory for regulated risk
?
Evaluation suite is older than the current draft
lawcrew-regression-v7 · last run 6 days ago
Abstention queue owner assigned
evidence-gap-queue · N. Sundaram, 15 Aug · FR-EVD-004
?
No outcome unit declared for this crew
outcome_unit: unset · FR-OUT-001

Effect Declaration

Compiler verified
Proved No path from untrusted document intake to side-effects:external without a human gate.
Proved Client data never reaches a model profile outside residency:SG.
Proved Worst-case spend bounded at S$4.40 across all branches.
Unbounded Loop iteration count cannot be bounded until the blocking issue above is fixed.
Selected node
Evidence Research Pod
pod://evidence-research@3.2.0
Version policy
Model profile
Resolves to Claude Sonnet 5 · residency SG
Knowledge Packs
SG Statutes & Case LawFirm Clause Library
Evidence floor
A Sufficiency Score below this floor triggers an Abstention, routed to the Evidence Gap Queue rather than answered.
Effect Declaration
reads:knowledgereads:web(allowlist)spend:≤S$1.50
Limits
Timeout
180s
Retries
2
Max cost
S$1.50
On failure
Escalate
Evaluation
94.2%
Vibe · proposed change
Add a second reviewer that argues the tenant's side, and cap the revision loop at three passes.
I will add Opposing Counsel Reviewer from the Hub (verified, used by 6 crews) in parallel with the existing reviewer, and set max_iterations: 3 on the revision edge. This resolves one blocking validation issue.
nodes: + - id: opposing-review + uses: agent://opposing-counsel@1.4.0 + model_profile: writing-premium edges: - - from: adversarial-review.fail - to: clause-drafter + - from: adversarial-review.fail + to: clause-drafter + max_iterations: 3 + on_exhausted: escalate
Accepting creates draft v3.1.0-draft.4. Production is unaffected until a release is approved.

Knowledge

Governed Knowledge Packs, not an attached vector store. Every pack carries ownership, access rules, authority tiers, freshness windows and its own retrieval evaluation.

Packs
11
Across 4 workspaces
Documents
48,214
1.2M chunks indexed
Stale sources
2
14 artefacts affected
Conflicts open
3
Authorities disagree

Knowledge Packs

PackSourcesAuthorityFreshnessAccessRetrieval evalState
SG Statutes & Case Law
Maintained by Singapore Legal Practice Pack
6 feedsPrimaryWeekly · 2d ago Legal workspace0.91Current
MAS Circulars
Maintained by MAS Financial Compliance Pack
3 feedsPrimaryDaily · 4d ago Finance workspace0.88Stale
Firm Clause Library
Tenant-owned · uploaded precedents
1,842 docsSecondaryOn change Legal · partners only0.86Current
Ridgeway Firm Knowledge
Handbooks, SOPs, brand and tone
412 docsInternalMonthly All workspaces0.83Current
Sanctions & PEP Lists
MAS Financial Compliance Pack
6 feedsPrimaryDaily Compliance0.94Current
PDPA Guidance
Regulator publications and advisories
2 feedsPrimaryExpired 12d All workspaces0.79Expired

Staleness impact

14 artefacts
When a source expires, KrewOS flags every artefact that relied on it — not just future runs.
14
MAS Circulars · 4 days stale
14 published artefacts cited this pack · 3 crews affected
6
PDPA Guidance · expired
6 artefacts · retrieval now blocked by freshness policy

Source conflicts

3 open
Where authorities disagree, retrieval surfaces both positions rather than silently picking one.
Notice period for commercial break clauses
Firm precedent says 3 months · recent judgment implies 6
Unresolved
FX revaluation treatment at period end
MAS circular 2024-08 vs internal finance SOP
Unresolved
Screening threshold for a beneficial owner below 25%
Resolved by domain expert · SOP updated
Resolved

Models & Secrets

Crews reference capability profiles and aliases, never a provider name. Policy is enforced at the gateway, outside the prompt.

Spend this month
S$4,182
62% of S$6,750 budget
Tokens
184M
In 142M · out 42M
Fallbacks fired
6
All within approved chain
Policy blocks
2
Residency violation prevented

Model profiles

Aliases resolve at compile time
AliasResolves toCapabilitiesResidencyKeyBudgetHealth
research-standardClaude Sonnet 5 Long context · tool use · structuredSG PlatformS$1,940 / 2,500 Elevated latency
writing-premiumClaude Opus 5 High reasoning · long context · multilingualSG Tenant BYOKS$1,610 / 2,400 Healthy
classify-fastClaude Haiku 4.5 Low latency · structured outputSG PlatformS$284 / 900 Healthy
vision-extractClaude Opus 5 Vision · document layoutSG Tenant BYOKS$348 / 700 Healthy
local-privateSelf-hosted · customer VPC Text · structured outputOn-prem CustomerNot metered Healthy
legacy-generalThird-party general model TextUS PlatformBlocked Not allowlisted

Routing & fallback

research-standard
  primary    Claude Sonnet 5 · SG
  fallback_1 Claude Opus 5 · SG          when: rate_limit | 5xx
  fallback_2 local-private                when: provider_outage
  fail_closed true  · no unapproved provider is ever reached

data_policy
  classification  client-confidential
  residency       SG only
  retention       zero-retention endpoints required
  on_violation    block + audit event
Two runs were blocked this month when a forked crew attempted legacy-general with client-confidential data. Fail-closed behaviour held; no data left the region.

Secrets

All referenced
anthropic-tenant-key
ref://vault/ridgeway/anthropic-sg · rotated 18d ago
Active
gebiz-api
ref://vault/ridgeway/gebiz · rotated 41d ago
Rotate soon
xero-oauth
ref://vault/ridgeway/xero · rotated 6d ago
Active
n8n-webhook-signing
ref://vault/ridgeway/n8n · rotated 9d ago
Active
Secret values are never returned by any API, log, prompt, manifest or export. Only opaque references appear in platform metadata.

What BYOK changes on your bill

2 profiles on tenant keysshadow-metered
Model credits charged
0 · this month and every month
Inference billed by
Your provider, at your rates
Notional model cost
S$1,958.00 shadow-metered
Platform credits
Charged in full
What that covers
Orchestration, retrieval, Evidence storage, evaluation, human tasks, audit retention
Debited from
The same wallet · Credits & Billing
writing-premium
S$1,610 · your provider
vision-extract
S$348 · your provider
Charged to you by us
S$0.00 on both
Bringing your own keys zeroes the model meter and nothing else. The platform work a run does either side of the model call — routing, retrieval, evidence capture, deterministic checks, approvals, audit — is a platform service whoever pays for inference, so platform credits are charged in full.
The notional cost is still metered, it is simply never debited. Without it, nobody could answer what this crew would cost on managed keys, whether a rate card change affects you, or which model tier a routing decision should prefer. It appears on your usage records and on no invoice.

Tools & Connectors

Tools read and compute. Actions cause external side effects and carry stronger controls — idempotency, approval and compensation.

Read tools
28
No side effects
Actions
9
All require approval
Invocations today
3,412
6 permission denials
Duplicate actions
0
Idempotency held

Registry

AllToolsActionsMCP
CapabilityClassTransportApprovalIdempotencyCalls 24hHealth
Knowledge Retrieval
Hybrid search over authorised packs
ReadinternalNonen/a2,104Healthy
GeBIZ Opportunity Feed
Singapore government tender listings
ReadRESTNonen/a412Healthy
Xero Ledger Query
Read-only accounting extract
ReadOAuthNonen/a188Healthy
ACRA Registry Search
Company, officer and shareholding records
ReadRESTNonen/a576Healthy
CMS Publish
Publishes an article via n8n workflow
Actionn8nMandatoryarticle_id+rev18Healthy
CRM Opportunity Write
Creates or updates a pipeline record
ActionRESTMandatoryexternal_ref31Healthy
Client Document Return
Sends reviewed documents to the client portal
Actionn8nDualmatter_id+rev7Healthy
eFiling Submission
Quarantined pending security review
ActionRESTMandatoryfiling_ref0Quarantined

MCP · inbound

Crews as tools
Deployed crews are exposed as MCP tools. Staff can invoke a governed crew from Claude, Copilot or any MCP client — evidence, policy and approval still apply, because they are enforced in the runtime, not the interface.
krewos.lawcrew_review
Dual approval enforced · 41 calls this week
Live
krewos.evidence_research
Read-only · 214 calls this week
Live
krewos.tender_screen
Read-only · 88 calls this week
Live

MCP · outbound

External servers
Any approved MCP server becomes an available Tool, so the connector surface grows without KrewOS building each integration.
sg-legislation-mcp
4 tools · read-only · allowlisted
Connected
internal-docs-mcp
2 tools · tenant-scoped
Connected
vendor-crm-mcp
6 tools · 2 write actions withheld
Partial
RUN-8F2C41Running · node 7 of 11

Tenancy agreement · Tanglin Holdings

LawCrew Document Review v3.0.2 · started 14:02 SGT · operator-initiated by Priya N.

Release
v3.0.2 Verified
Evidence
31 sources · Sufficiency Score 0.88
Approval
Dual · pending
Credits
218 settled of 478 reserved
Budget
S$2.18 of S$4.40
Checkpoint
ck-7a · 40s ago

Execution trace

AllModel callsRetrievalDecisions
Intakedeterministic
Parsed 1 document · 42 pages · layout extracted · SHA a1f4…9c22
4.1s · 0 cr
Jurisdiction Routerclassify-fastSingapore
Governing law clause 24.1 · confidence 0.96 · routed to SG legal branch
2.8s · 1 cr
Evidence Research Podpod@3.2.0Sufficiency 0.88
5 internal nodes · 31 sources retrieved · 3 rejected on authority tier · 1 conflict surfaced
sg-statutes · Conveyancing and Law of Property Act 1886 s.6(1) · retrieved 14:03 SGT · primary
“No action shall be brought upon any contract for the sale or other disposition of immovable property…unless the agreement is in writing and signed.”
conflict · notice period for break clause
Firm precedent library specifies 3 months. Lim v Everline Realty [2025] SGHC 118 implies 6 months where the tenant is a body corporate. Both positions carried forward to drafting.
48.2s · 94 cr
Clause Drafterwriting-premium
7 amendments drafted · each linked to supporting evidence · 2 flagged as unusual
36.4s · 71 cr
Risk Checksdeterministic5 of 6 passed
Indemnity cap absent — rule RISK-SG-014 raised to review rather than blocking
0.9s · 0 cr
Adversarial Reviewerwriting-premiumRunning
Challenging amendment 4 of 7 · revision pass 1 of 3
21.7s · 52 cr
Partner Sign-offhuman · dualQueued
Will assign to Legal Partners group on completion
Return to Clientaction · idempotentBlocked
Requires both approvals. Idempotency key RH-2291+r3 reserved.

Run queue

215 today
RUN-8F2B90
Content Studio · editor gate
Waiting
RUN-8F2951
Finance Close · abstained
Gap
RUN-8F29E3
AML Screening · sanctions escalation
Escalated
RUN-8F2A17
BizDev · 14 opportunities
Done
RUN-8F28C4
Matter Intake · connector timeout
Failed
RUN-8F2D07
Content Studio · parked at ck-5b · 68h left
Awaiting credit
A run never dies of an empty wallet. It degrades to the cheapest alias meeting each node's declared capability, withholds every new side-effect Action, runs into the tenant overdraft, then checkpoints and parks with all Artefacts and Evidence committed. It resumes from that checkpoint on top-up within 72 hours, and ends in a distinct expired unfunded state — reported separately from failure — if the window closes first.

Cost breakdown

Evidence Research Pod
94 cr · S$0.94
Clause Drafter
71 cr · S$0.71
Adversarial Reviewer
52 cr · S$0.52
Router & checks
1 cr · S$0.01
Settled so far
218 cr · S$2.18
Reserved at admission
478 cr
Still held
260 cr
Budget ceiling
S$4.40
Two independent gates admitted this run. The hard budget cap was evaluated first and fails closed before any spending; the reservation of 478 credits — the P90 estimate plus 15%, rounded up — was then checked on its own account. The 260 credits still held are a hold and not a spend, so they count against no budget, and releasing them at close returns nothing to one.

Incident

1 open
LT
Provider latency degraded
research-standard · p95 up 2.4× · fallback armed

Approval Workbench

Reviewers see the decision, not a wall of output: what changed, what is risky, which sources support it, which checks failed, and what happens next.

Assigned to you
2
1 overdue
Team queue
7
Median wait 22 min
Sampled today
23%
Risk-weighted Review Sampling
Abstentions
3
Evidence below declared floor
Edit rate
11%
−6pt this quarter
41m
Professional sign-off
LawCrew · Tanglin tenancy · dual
Overdue
2h
Publication approval
Content Studio · bilingual article
Due
GAP
Abstention · FX revaluation
Finance Close · sufficiency below floor 3×
Review
SAN
Sanctions escalation
AML Screening · PEP match on a beneficial owner
Escalated
SMP
Sampled quality check
BizDev · opportunity scoring
Sampled

Professional sign-off · Ridgeway tenancy review

RegulatedOverdue 41m
Decision requested: approve the reviewed agreement and 7 drafted amendments for return to the client. On approval, Client Document Return executes and the matter closes. On rejection, drafting reruns with your notes — no other node re-executes.
Why this reached you
PolicyRisk level regulated requires dual professional approval before any external Action.
CheckDeterministic rule RISK-SG-014 — no indemnity cap present in clause 18.
ConflictAuthorities disagree on break-clause notice period. Both positions are carried in the memo.
Amendments · 7 drafted, 2 flagged
ClauseChangeAuthorityFlag
18.2Insert liability cap at 12 months' rentFirm precedent · 41 mattersUnusual absence
24.4Extend break notice from 3 to 6 monthsLim v Everline [2025] SGHC 118Conflict
9.1Clarify service charge apportionmentFirm precedent · 112 mattersRoutine
31.0Add PDPA-compliant data handling clausePDPA s.24 · firm templateRoutine
+3 moreTypographical and cross-reference fixesRoutine
Supporting evidence · 31 sources
Lim v Everline Realty [2025] SGHC 118 at [44] · primary · retrieved 14:03 SGT
“Where the tenant is a body corporate, a three-month notice period will rarely afford a reasonable opportunity to vacate commercial premises of this scale.”
Firm Clause Library · standard commercial lease v9 · secondary · internal
Standard break clause specifies three months' written notice, used in 38 of 41 comparable matters since 2023.
Second approver: K. Rahman · not yet actioned
Your decision and any edits are captured as an immutable Correction Record, linked to this run, release, component and reviewer, and retained as a candidate Evaluation case. 1,847 Correction Records have been absorbed by this crew to date.

Autonomy & Review

Progressive Autonomy: every crew enters production at full review and graduates through Review Sampling only once measured accuracy holds across a meaningful sample — and reverts automatically if it slips.

Blended review rate
23%
Down from 100% at launch
Reviewer hours saved
312/mo
Against full-review baseline
Sampled escapes
2
Both caught, crews reverted
Eligible to graduate
1
AML Screening Advisory

Autonomy ladder

Confidence bounds from risk-weighted Review Sampling
CrewStageReview rateMeasured accuracyReviewed sampleError boundTrend
LawCrew Document Review
Regulated · dual approval
Regulated floor100%91.4% 2,104n/aNot eligible for sampling
Finance Close & Reporting
Financially sensitive
Full review100%93.8% 684n/aEligible at 1,000 reviewed outcomes
AML Screening Advisory
Regulated · specialist escalation
Supervised sampling10%97.1% 1,442<1.4% @ 99%Ready for extended at 5%
Content Studio
Operational
Extended sampling15%96.2% 3,318<1.9% @ 99%Holding
BizDev Intelligence
Operational
Supervised sampling25%94.8% 1,908<2.6% @ 99%Improving
Matter Intake Triage
Operational · reverted 6 Aug
Supervised sampling40%89.7% 742<5.1% @ 99%Reverted from extended, 20%

The four stages

Autonomy Policy · versioned per crew
StageEntry conditionReview rateReversion trigger
Full review Default on first production deployment. 100% Not applicable; this is the floor.
Supervised sampling Required reviewed volume met at or above required accuracy, plus a clean period. Declared rate with published confidence bound. Any sampled failure in a regulated class, or two in any class within the escape window.
Extended sampling Sustained accuracy at the previous stage with no escape in the clean period. Reduced rate, floor set by risk class. As above, returning to the previous stage.
Regulated floor Applies permanently to regulated and safety-critical outputs. 100%, dual where configured. Not eligible for sampling.

Graduation candidate

Eligible
AML Screening Advisory · supervised → extended sampling
10% → 5%. 1,442 reviewed outcomes over 94 days. Accuracy 97.1%, no sampled escape in 61 days.
Required sample
1,000 ✓
Required accuracy
≥96% ✓
Clean period
60d ✓
Sanctions cases passing
100% ✓
Est. hours released
18 / month
Safety-critical and regulated nodes stay at the regulated floor regardless of the crew's stage. Only advisory outputs are eligible for Review Sampling.

Reverted · Matter Intake Triage

Auto-reverted
Two sampled failures within the escape window breached the threshold. The crew returned from extended sampling (20%) to supervised sampling (40%) automatically and an incident was opened.
Escape 1
3 Aug · wrong practice area
Escape 2
6 Aug · stale conflicts register
Root cause
Source freshness
Fix released
v2.3.1
Re-graduation at
500 clean outcomes
Both escapes were converted into regression cases and now run on every release.

Reviewer calibration

1 flag
ReviewerAgreementMedian timeSignal
N. Sundaram0.946m 20sCalibrated
K. Rahman0.918m 04sCalibrated
Priya N.0.895m 12sCalibrated
J. Wong0.710m 38sPossible rubber-stamp
Approval speed well below cohort median with low agreement suggests decisions are not being read. Sampling weight for this reviewer has been increased pending a conversation.

Evaluation Lab

Evaluations are product assets, not a pre-launch chore. Correction Records flow back in as cases, and no release passes a failed mandatory threshold without an audited override.

Suites
34
4,182 cases total
Correction Records
1,847
+214 this month
Promoted to cases
612
After expert confirmation
Releases blocked
3
This quarter
Overrides
1
Audited, with reason

Suites

Thresholds gate release
SuiteScopeCasesPass rateThresholdCostLast runGate
lawcrew-regression-v7Crew · end to end312 94.6%92%S$41.206d agoPass
lawcrew-adversarial-v3Safety · injection, leakage148 88.5%95%S$18.906d agoBlocking
evidence-research-goldenPod · retrieval quality204 94.2%90%S$22.402d agoPass
content-studio-regressionCrew · bilingual output286 96.2%93%S$34.101d agoPass
aml-screening-v4Regulated · sanctions match96 99.0%100%S$9.803d ago1 failure
cost-latency-envelopeAll crews · budget62 100%100%S$6.201d agoPass

Blocking failure

Release held
lawcrew-adversarial-v3
88.5% against a 95% mandatory threshold. 17 of 148 cases failed.
CategoryFail
Injection via retrieved document text11
Unsupported claim without citation4
Over-authority in recommendation tone2
Release v3.1.0 cannot be deployed to production until this threshold is met or a tenant administrator records an audited override with reason.

Correction flywheel

Correction RecordContinuous
Regression pass rate · LawCrew, 12 months
Sep 2025 baseline
82.0%
Current
94.6%
Correction Records absorbed
1,847
Promoted to cases
612
Reviewer edit rate
11% −6pt
Every approval, rejection and edit is captured as an immutable Correction Record. Domain experts confirm each one before promotion into an Evaluation case, so the suite grows out of real disputed work rather than authored fixtures.

Model migration

Comparison ready
Content Studio on writing-premium vs candidate writing-premium-v3, across 286 regression cases.
MeasureCurrentCandidate
Pass rate96.2%97.4%
Evidence coverage0.910.93
Cost per runS$1.42S$1.71
P95 latency94s71s
Bilingual parity0.880.85
Quality and latency improve; cost rises 20% and Chinese-language parity regresses slightly. Recommend a canary at 10% before full promotion.

Release & Deployment

A release pins every component, model policy, knowledge version, connector, policy and evaluation suite. Production is immutable — updates create a new release, and rollback returns to one already approved.

Development
v3.1.0-draft.4 Unvalidated
Test
v3.1.0-rc.2 Gate failed
Production
v3.0.2 Healthy · 41d
Rollback target
v2.9.4

Release candidate · LawCrew v3.1.0-rc.2

Blocked
Release gates
GateRequirementResultState
Manifest validationNo blocking issues0 blockingPass
Effect DeclarationNo unguarded side effectsprovedPass
Regression suite≥ 92%94.6%Pass
Adversarial suite≥ 95%88.5%Fail
Cost envelope≤ S$4.40 / runS$4.12Pass
Security reviewSigned offN. Sundaram · 11 AugPass
Domain approvalLegal ownerNot requestedPending
Deployment is blocked while a mandatory threshold fails. A tenant administrator may record an audited override with a written reason; the override, its author and its justification are attached to the release permanently.

Locked dependencies

sha256:7d4a…e1b8
DependencyKindPinnedChange from v3.0.2
pod://evidence-researchPod3.2.03.1.4 → 3.2.0
agent://opposing-counselAgent1.4.0Added
agent://clause-drafterAgent4.1.2Unchanged
policy://sg-legal-gatesPolicy1.8.0Unchanged
knowledge://sg-statutesKnowledge2026.08.13Refreshed
action://client-returnAction2.0.1Unchanged

Deployment targets

Authenticated API
POST /v1/crews/lawcrew/runs
Live
MCP tool
krewos.lawcrew_review
Live
Operator case workflow
Matter intake queue
Live
Scheduled
Not configured
Off

Rollout plan

Strategy
Canary
Initial share
10%
Promotion after
200 runs
Auto-rollback on
Quality −2pt
Shadow comparison
Enabled
In-flight long-running cases continue on their originating release. Rollback never re-plans a case mid-execution.

Recent releases

v3.0.2
Deployed 5 Jul · current
Healthy
v3.0.1
Deployed 19 Jun · superseded
Retired
v3.0.0
Rolled back 17 Jun · cost regression
Rolled back
v2.9.4
Rollback target · verified
Ready

Developer Bridge

Export is an engineering-ready repository, not a proprietary format. Managed definitions and custom extension zones are separated so round-trips stay honest.

Mode
Linked
Repository
ridgeway/lawcrew-review
Branch
feat/opposing-counsel
Import status
2 changes to review
Secrets in export
None

Generated repository

lawcrew-review/
├── crew.yaml              managed
├── README.md
├── AGENTS.md              managed
├── CLAUDE.md              managed
├── agents/                 managed
│   ├── jurisdiction-router.yaml
│   ├── clause-drafter.yaml
│   └── adversarial-reviewer.yaml
├── pods/                   managed
├── workflows/              managed
├── schemas/                managed
├── prompts/                managed
├── knowledge/              managed
├── policies/               managed
├── evaluations/            managed
├── tools/                  custom
│   ├── matter-intake.ts
│   └── client-portal.ts
├── extensions/             custom
│   └── sg-risk-rules.ts
├── tests/
├── deployment/
└── .env.example            no values

Inbound changes

Review required
Custom tool added · client-portal.ts
Implements Component Contract · tests pass · dependency scan clean
Representable
Prompt revised · adversarial-reviewer.yaml
Supported managed-file edit · diff available in Studio
Representable
!
Workflow restructured outside managed zone
workflows/customer-flow.yaml · hand-edited edges cannot be shown on the canvas
Unsupported
You can import the two representable changes and leave the third in the repository, or eject this project and take ownership of its architecture. Ejecting removes the guarantee of visual re-import but keeps full runtime API access.

CLI

krewos 1.4.0
$ krewos validate
   manifest schema 2.0 · 11 nodes · 3 pods
   effect declaration · no unguarded side effects
  ! loop adversarial-review → clause-drafter now bounded at 3

$ krewos eval run lawcrew-adversarial-v3 --env test
  148 cases · 131 pass · 17 fail · 88.5% · S$18.90
  threshold 95% not met — release gate would block

$ krewos release prepare --from test
  blocked: 1 mandatory gate failing

Component contract

// tools/client-portal.ts
export default defineAction({
  id: "client-document-return",
  input: ClientReturnSchema,
  effects: ["side-effects:external", "writes:client-portal"],
  idempotency: (i) => `${i.matterId}+${i.revision}`,
  approval: "dual",
  compensate: async (ref) => portal.withdraw(ref),
  timeout: 30_000,
})
The Effect Declaration, idempotency and compensation are part of the contract, so a custom tool is governed by the same rules as a built-in one the moment it is registered.

Cost & Outcomes

What each crew costs per outcome unit — the unit of business work it declares — and what it replaces. The same numbers that control budgets make the value legible.

Credits, 30 days
128,400
S$1,284 · models, tools and runtime
Outcomes delivered
2,914
Across 6 crews
Blended cost / outcome unit
S$1.44
−18% vs Q1
Human hours saved
1,208
Against configured baselines

Cost per outcome unit

Baseline is the manual cost your team configured
CrewOutcome unitOutcomesCost eachHuman minutesManual baselineSaving eachTrend
LawCrew Document ReviewMatter reviewed 218S$3.9422S$186.00 S$118.40Improving
Content StudioArticle published 412S$1.426S$92.00 S$78.10Improving
BizDev IntelligenceOpportunity qualified 1,104S$0.613S$34.00 S$28.90Improving
AML Screening AdvisoryScreening advisory issued 684S$0.872S$58.00 S$52.10Holding
Finance Close & ReportingReconciliation closed 46S$8.2048S$240.00 S$86.40Full review
Matter Intake TriageEnquiry triaged 450S$0.644S$22.00 S$14.20Review rate up

Where spend goes

writing-premium
S$1,610 · 38%
research-standard
S$1,940 · 46%
vision-extract
S$348 · 8%
classify-fast
S$284 · 7%
Tools & connectors
S$0 · metered separately
Total
S$4,182
Research is the largest line. Routing low-stakes retrieval to classify-fast would cut roughly S$340 a month at no measured quality cost.

Blended cost per outcome unit

−18% vs Q1
Sep 2025
S$2.42
Current
S$1.44
Driver · model routing
−S$0.41
Driver · caching
−S$0.28
Driver · fewer retries
−S$0.29

Budget guards

All within limits
Tenant monthly62%
Legal workspace71%
Finance workspace38%
Content workspace54%
On reaching a soft limit the runtime degrades model tier before it fails a run. Hard limits stop new model work and side-effect Actions outright.
Credits are a second and independent gate, and a run must pass both. A run inside every budget here is still refused if its reservation cannot be covered. Exhausting credits mid-run degrades and parks rather than stopping, which is precisely what separates it from a hard budget ceiling, where model work and Actions both halt before any further spending.

Credits & Billing

One credit is a prepaid claim on S$0.01 of platform services, priced through the rate card version pinned to your contract. Credits sit in lots, each with its own price, expiry and refundability, because what you paid for a credit decides what it is worth back.

Available
161,014 S$1,610.14
Held on live runs
1,486 4 runs
Overdraft used
0 of 25,000
Runway
38d4,280/day
Consumed, 30 days
128,400 S$1,284.00
Auto top-up at
50,000 available
2,200 goodwill credits expire on 12 November. That is lot_0402, granted on 14 August as remediation for incident INC-0224. The 30-day notice is due to your billing contact on 13 October, the 7-day notice on 5 November and the 1-day notice on 11 November. It is also the lot being drawn first, because consumption takes promotional credits, then goodwill, then purchased lots by earliest expiry, so at the current rate it will be spent within the day and expire holding nothing. The notice fires on the calendar, not on the forecast — you are told either way.

Credit lots

rate card v4Consumption draws promotional, then goodwill, then purchased by earliest expiry
LotSourceOriginalRemainingCash receivedEffective rateTreatmentRefundableExpires
lot_0402Goodwill grant · INC-0224 · ADJ-02312,2002,200S$0.00Contra-revenueNo12 Nov 2026
lot_0417Purchased bundle · INV-2026-0402240,000160,300S$2,064.00S$0.008600Deferred revenueYes09 Aug 2027
Remaining across all lotsLess 1,486 held on live runs162,500Available: 161,014
Why lots and not one balance. A credit granted in goodwill after an incident and a credit bought at S$0.0086 in a 240,000 bundle are not interchangeable when it comes to what they are worth back to you, when they lapse, or whether they can be refunded at all. Goodwill credits are never refundable in cash, and they are drawn first, so a concession is realised before you pay for anything. Reporting a single number would hide all three facts, so the balance above is the sum of the lots and the lots stay visible.

Top up

SGD
BundlePriceEffective rateSaving
60,000S$570.00S$0.0095005%
120,000S$1,092.00S$0.0091009%
240,000S$2,064.00S$0.00860014%
600,000S$4,980.00S$0.00830017%
Bundles are valid twelve months from purchase and create a lot of their own at the price you paid. Credits are granted when payment clears, not when the invoice is raised.

Automatic top-up

Enabled
Trigger threshold
50,000 credits available
Bundle purchased
240,000 · S$2,064.00
Monthly cap
2 bundles · S$4,128.00
Used this month
0 of 2
Failed payment
3 retries over 72h, then notify
Next expected
11 Sep 2026
The cap is the thing to watch, not the threshold. Two bundles at the cap add 480,000 credits, which is 112 days at your current burn. A third would need the cap raised, and automatic top-up disables itself the moment the tenancy goes past due — so a card that fails on 11 September turns into a funding problem in October, not a surprise at the year end.

Rate card & contract

Pinned
Pinned version
v4 · since 15 Mar 2026
Contract term
15 Mar 2026 — 14 Mar 2027
Plan
Professional · S$4,200 / mo
Included credits
None · credits are purchased as bundles
Migration notice
60 days
Migration pending
None
Publishing a new rate card does not touch you. Your contract pins v4 for its term, migration is a deliberate action with 60 days' notice recorded before the pinned version changes, and a run that has already been admitted finishes on the version it started with. Rate increases are absorbed inside the term and passed through only at renewal.

What happens when credits run short

Overdraft ceiling 25,000 · currently unused
Funded Degraded Overdraft Parked Expired unfunded
A run is never killed for running out of credit inside its funding window. It first degrades — cheapest model alias that still meets the node's declared capability, reduced concurrency, narrower retrieval — and stops starting any new side-effect Action. It then draws on the overdraft. Only when that is exhausted does it checkpoint and park, holding every artefact and evidence item already produced, and it resumes by itself the moment you top up.
The window is 72 hours and it does end. A run still unfunded when it closes terminates as expired unfunded, which is reported separately from failure because it is a funding outcome and not a fault of ours. Everything already committed is retained under your retention policy. Overdraft is recovered from the next grant before any other allocation, so the first credits you buy repay it.

Invoices & Statements

Every invoice, in the form it was issued. An issued invoice is never amended or deleted — a correction is a void and reissue, or a credit note, and each of those is its own numbered document.

Outstanding
S$4,578.00 due 26 Aug
Next invoice
01 Sep 2026 draft open
Paid, 12 months
S$52,131.21
Payment terms
Net 30 card ••2058
GST
9% 201812345K

Invoices

All statesSGDNewest first
NumberPeriodLinesSubtotalGST 9%TotalState
INV-2026-0451Sep 2026Subscription · issues 01 SepS$4,200.00S$378.00S$4,578.00Draft
INV-2026-0436Aug 2026SubscriptionS$4,200.00S$378.00S$4,578.00Issued · due 26 Aug
INV-2026-0402Aug 2026Credit bundle 240,000S$2,064.00S$185.76S$2,249.76Paid
INV-2026-0330Jun 2026SubscriptionS$4,200.00S$378.00S$4,578.00Paid
INV-2026-0064Feb 2026Subscription · availability service creditS$3,762.80S$338.65S$4,101.45Paid

Invoice detail · INV-2026-0064

Paid 24 Feb 2026Feb 2026
Supplier
KrewOS Cloud · wGrow Technologies Pte Ltd
GST reg. no.
201812345K
Invoice date
01 Feb 2026
Due date
03 Mar 2026
Customer
Ridgeway Legal LLP
UEN
201933471C
Currency
SGD
Terms
Net 30
GST treatment
Standard-rated 9%
Rate card
v3
Paid
24 Feb 2026, 09:31
Method
Corporate card ••2058
LineDetailQtyUnitAmount
Platform subscriptionProfessional · 1–28 Feb 2026S$4,200.00
Availability service creditJanuary 2026 · attainment 99.84% against 99.9% · tier 10% of a base of S$4,372.00−S$437.20
Subtotal excluding GSTSubscription line spread across the month it fundsS$3,762.80
GST at 9%The credit carries the tax treatment of the supply it reducesS$338.65
Total including GSTSettled in full 24 Feb 2026S$4,101.45
Nobody claimed this. January was served at 99.84% against a committed 99.9%, so the credit was issued automatically from the published attainment figure and appeared on the next invoice raised in draft. There is no claim form and no window in which to file one, because a remedy you have to ask for is one most customers never receive.
It is money, not credits. The line reduces what you owe. It creates no credit lot, carries no expiry, and is not the goodwill remediation that does. Credits that lapse before you can spend them are not compensation for a month the platform did not work — and if you leave, an unapplied remainder is paid out in cash rather than written off.

Line types you will see

SUB
Platform subscription
Spread evenly across the period it funds
BUN
Credit bundle purchase
Creates a lot at the price paid
ENT
Plan-included entitlement
Creates the monthly allowance lot
OVR
Metered overage
Charged to the month it consumed
PCK
KrewOS Pack licence
Spread across the licence period
SVC
Professional services
Attributed to the month of supply
ASC
Availability service credit
Negative · bears no credits · creates no lot

If a credit exceeds the invoice

February's credit was S$437.20 against a S$4,200.00 subscription, so it was applied in full and nothing was left over. Where a credit is larger than the invoice it lands on, the balance is not lost: it carries forward without expiry to the following invoice, and keeps carrying until it is used up. It is never applied to an invoice already issued — that document stands as it was.

Corrections

VD
Void and reissue
The original is retained, marked void, and a new number is issued
CN
Credit note
Its own numbered document, linked to the line it corrects
RV
Fault reversal
Credits consumed by a run we broke are returned to the lots they came from, with no request from you

Administration

Tenancy, identity, policy, entitlements and audit for Ridgeway Legal LLP.

Workspaces
4
12 projects
Users
38
SSO via Entra ID
Audit events 30d
184k
Immutable, exportable
Privileged sessions
2
Time-limited, approved
Isolation tests
Pass
Nightly, 214 assertions

Workspaces & environments

WorkspaceProjectsEnvironmentsBudgetResidency
Legal3dev · test · prodS$2,400SG
Finance2dev · test · prodS$1,800SG
Content4dev · prodS$1,600SG
Compliance3dev · test · prodS$950SG

Roles

RoleUsersProductionSecretsPublish
Business Builder14Request onlyNoneNo
Domain Expert9Approve domainNoneNo
AI Engineer5Prepare releaseReferencesYes
Operator4Run controlNoneNo
Tenant Administrator3FullManageYes
Auditor3Read-onlyNoneNo

Seats

14 of 15 builder16 of 100 reviewer
Seat classRoles it confersMetered asSeats
EngineerAI Engineer · Business BuilderBuilder5
BuilderBusiness BuilderBuilder9
ReviewerDomain ExpertReviewer9
OperatorOperatorReviewer4
AuditorAuditorReviewer3
AdministratorTenant AdministratorNot metered3
33 people38 role grants · 5 people hold two33
A seat binds one person to one seat class, and the seat class declares the fixed set of roles it confers. That is deliberate: the record your bill counts and the record access control reads are the same record, so there is no way to be charged for a seat that grants nothing, or to hold a role that no seat pays for. The roles table above is derived from this one.

Credit notifications

billing contact
Billing contact
L. Tan, Finance Manager · finance@ridgewaylegal.example
Also notified
Every Tenant Administrator · 3 people
DEG
Run entered credit-degraded operation
Immediate · the run is still going, on a cheaper alias
On
PRK
Run parked, awaiting credit
Immediate, then at 24h, 48h and 68h through the 72-hour window
On
EXP
Run expired unfunded
Immediate · reported separately from run failure
On
LOT
Credits approaching expiry
30, 7 and 1 days before a lot lapses
On
LOW
Balance reached the top-up threshold
At 50,000 available, whether or not automatic top-up fires
On
TOP
Top-up succeeded or failed
Every attempt, including each of the three retries
On
Parking and expiry notices cannot be switched off. A run that stops because it ran out of money is not something you should be able to stop being told about.

Data & retention

Residency
Singapore only
Run artefacts
7 years
Traces & logs
90 days
Audit events
7 years, immutable
Evidence excerpts
7 years
Model prompts
30 days, redacted
Right to delete
Enabled
Encryption keys
Customer-managed

Entitlements

Maintained Pack subscriptions
Singapore Legal Practice Pack
Annual · renews 1 Mar 2027
Active
MAS Financial Compliance Pack
Annual · renews 1 Nov 2026
Active
Conveyancing & Property Pack
Trial · 18 days remaining
Trial
KrewOS Cloud Dedicated
Runtime tier · SG region
Active

Audit stream

Release override recorded
14:41 · N.Sundaram · lawcrew v3.1.0-rc.1
Model policy blocked a run
13:08 · legacy-general · residency
Privileged support session opened
11:22 · 2h limit · approved
Capability quarantined
09:47 · efiling-submission
Autonomy reverted
06 Aug · Matter Intake · 20% → 40%

Memory

Knowledge is what the firm knows and can cite. Memory is what a Crew carries between turns, cases and releases. They are kept apart deliberately: a retrieved citation earns its authority from its source, whereas a memory record earns it from whoever approved the promotion.

Records
7,412
Across four tiers · 4 workspaces
Awaiting Curator
9
Oldest waiting 3 days
Promoted 30d
14
Of 61 proposed · 47 rejected
Expiring 14d
248
Session tier, retention policy
Blocked writes
3
Attempted permission escalation
Two rules make the tier model worth having, and both are enforced below the model rather than asked of it. Long-term memory is never a store of model-generated assumptions: nothing reaches it because a worker inferred it, only because a Curator or a deterministic policy admitted it, and the proposing Agent is recorded either way (FR-MEM-003, FR-MEM-005). And memory never grants a permission: a record may inform a decision, never widen what a Crew is allowed to read, spend or cause (FR-MEM-008). Three writes were refused this month for attempting exactly that, and each is on the audit trail below.

Working

Ephemeral
Records
in-flight only
Scope
One Node Run
Retention
Discarded at Run close
Write authority
The worker itself
Scratch space inside a single step. It never survives the Run, so it is never promoted and never reviewed.

Session / case

6,880
Records
6,880
Scope
One matter or case thread
Retention
Matter close + 90d
Write authority
Any Agent on the Crew
Everything the matter has established so far. Freely written, never consulted by another matter, and expired on the retention clock — 248 records fall due within 14 days.

Long-term

Curator-gated
Records
514
Scope
Workspace
Retention
Reviewed annually
Write authority
Curator approval only
Curated learning that outlives the matter that produced it. This is the tier that would rot into a store of assumptions if anything could write to it directly, which is why nothing can.

Core

Release-bound
Records
18
Scope
Tenant
Retention
Life of the tenancy
Write authority
Manifest change + Release
Standing facts about the firm itself. Changing one is a manifest edit that goes through diff, evaluation and an approved Release — it is configuration, not memory the platform writes.

Curator review queue

9 waitingSession → Long-term
A worker may propose; only a Curator or a deterministic policy admits. Provenance travels with the proposal, so a reviewer sees which Agent observed it, in which Run, and which Releases would begin relying on it (FR-MEM-005).
Proposed recordProposing AgentProvenanceAffected ReleasesBasisDecision
Tanglin Holdings prefers 60-day cure periods
Legal workspace · client preference
Clause AnalystRUN-8F2C41lawcrew v3.0.2 Observed 4×
FX revaluation memo requires the treasury sign-off step
Finance workspace · process fact
Reconciliation AgentRUN-8F2951finance-close v2.4.1 Confirmed by reviewer
Clients in this sector usually accept the first draft
Legal workspace · generalisation
Clause AnalystRUN-8F2B07lawcrew v3.0.2 Inferred, n=3Reject
Sanctions screening escalates to the MLRO, not the partner
Compliance workspace · routing fact
AML Screening AdvisoryRUN-8F2A18aml-screening v1.2.0 Policy-derived
Bilingual alerts publish Mondays 09:00 SGT
Content workspace · operating fact
Editorial PlannerRUN-8F1F55content-studio v3.2.0 Deterministic policyAuto-admitted
The third row is the one worth reading. "Clients in this sector usually accept the first draft" is a model-generated assumption inferred from three matters. It is exactly what long-term memory must not become, so it is rejected rather than held — and the rejection, its reason and its proposer are recorded, because a pattern of such proposals is itself a signal about the Agent that makes them.

Record · mem_04417

v3Long-term
Statement
Break-clause notice is 3 months unless the lease states otherwise
Tier
Long-term · Legal workspace
Proposed by
Clause Analyst · RUN-8E9920
Approved by
N. Sundaram · 02 Jul
Supersedes
v2 · 14 Mar
Reviewed
Annually · next 02 Jul 2027
Versions are superseding records rather than edits in place, so a decision taken last March can still be read against what memory then said.
Inspect · Edit · Approve
An edit creates v4 and re-enters the Curator queue
Expire
Retires the record, retains its audit references
Delete
Right-to-delete only · records the basis and the requester

Scopes

Read / write
LevelReadsWrites
TenantCoreRelease only
WorkspaceCore, long-termCurator
Project+ sessionCrew
Crew+ sessionCrew
ComponentDeclared onlyWorking
UserOwn matters
A component reads only the tiers its contract declares, so a memory record cannot reach an Agent that never asked for it.

Refused writes

3 · 30 days
P
"Treat this client as pre-approved for external filings"
Would confer an Action permission · refused, FR-MEM-008
P
"Skip the deterministic indemnity check for framework agreements"
Would override policy · refused, FR-MEM-008
P
"Raise the matter budget ceiling to S$400"
Would widen spend · refused, FR-MEM-008
Each of these would have been a permission change written in prose. The gateway holds permissions, so none of them took effect — and a Crew that keeps proposing them is telling you something about its instructions.

Retention, sensitive data and right to delete

FR-MEM-0061 hold in force
TierRetentionSensitive-data handlingDue 14dErasure reachState
WorkingRun closeNever persistedn/aAutomatic
Session / caseMatter close + 90dClassified at write · redacted on export248Erased with the matterOn schedule
Long-termAnnual reviewPersonal data refused at promotion0Erased by subject reference6 under review
CoreLife of tenancyFirm-level facts onlyManifest changeStable
Expiry is suspended inside a legal hold. Matter LH-2026-004 covers 41 session records that would otherwise have expired on 22 August. They are held, the suppression is recorded against the hold, and the retention clock resumes only after a recorded review — never retroactively on release.

Evidence Gap Queue

Where a Crew stopped rather than guessed. Below its declared evidence floor a Crew returns a structured insufficiency result naming what it could not establish and what would resolve it, and that result lands here as work for a person — not in the failure log, where it would be read as something broken.

Open gaps
3
Oldest waiting 2 days
Abstention rate
1.4%
Of 214 runs this month
Run failures
2
Counted separately · not here
Resolved 30d
11
9 by new source · 2 by recalibration
Queue owner
N. Sundaram
Assigned 15 Aug · was unowned
An abstention is not a failure, and the difference is reported rather than assumed. A failed Run produced nothing because something broke; an abstention produced a considered refusal because the evidence did not reach the floor the Crew Template declared. Counting them together would flatter the failure rate and hide the knowledge gap — so the two are reported apart, here and in Cost & Outcomes (FR-EVD-004).

Open gaps

All workspaces3 open
RunCrewClaim not establishedSufficiencyFloorWaitingState
RUN-8F2951Finance CloseFX revaluation treatment at period end
Abstained 3× on the same claim
0.610.722 daysOpen
RUN-8F2C88LawCrewBreak-clause notice period under the 2026 judgment
Authorities conflict · both positions carried
0.680.721 dayOpen
RUN-8F2D41AML Screening AdvisoryBeneficial ownership below the 25% threshold
Register silent · no adverse inference drawn
0.700.806 hoursSourcing
RUN-8F1E12Finance CloseLease incentive amortisation basis 0.660.72Closed 09 AugResolved
RUN-8F1A05Content StudioRegulator's position on comparative claims 0.590.70Closed 06 AugResolved
Three open gaps, and two of them name the same underlying absence: the firm holds no current authority on FX revaluation at period end. One gap is a question; the same gap arriving three times is a knowledge acquisition decision.

Insufficiency result · RUN-8F2951

Abstained
What could not be established
Whether the November MAS circular changes the revaluation basis for unhedged intercompany balances at period end. The Crew reached 0.61 against a floor of 0.72 and returned this rather than an answer.
What would resolve it
1
MAS Circular 2026-11, sections 4–6
Not in any pack · published 3 Nov, superseded 2024-08
2
Internal finance SOP, revaluation section
Present but 14 months stale · conflicts with the circular
3
Treasury's confirmation of the hedging position
Human input · no source can supply it
Ask
The route out of this queue runs through Knowledge, not through lowering the floor. Adding the circular and refreshing the SOP is the fix; moving 0.72 down to 0.60 would only stop the Crew telling you it was unsure.

Queue ownership

Assigned
Owner
N. Sundaram · Managing Partner
Escalation
Finance Close gaps → treasury
Target
Triaged within 1 business day
Validation
Clears FR-EVD-004
Studio flagged this queue as unowned until 15 August. An abstention routed to nobody is indistinguishable from an abstention discarded, which is why the manifest check refuses to pass a Crew that declares an evidence floor without naming who answers for what falls below it.

Gaps by claim type

90 days
Claim typeGapsTrend
Regulatory position7
Conflicting authority4
Missing register entry2
Stale internal SOP1
Recording the rate per Crew and per claim type turns a queue of interruptions into a map of what the firm does not yet know. Trend reporting lands at Core (FR-EVD-005).
Governed AI Agent Crews · Built in Singapore

AI crews for work that has to hold up.

Build, test and operate governed AI Agent Crews with source-backed evidence, named human approval and a complete audit trail on every run. Made for legal, financial, aquaculture and professional-services work.

30-day trial · development environment only · no production deployment on trial

Data residency
Singapore by default
Privacy
PDPA-aligned processing
Model keys
BYOK supported
Deployment
Customer-VPC available
Training
Never on your data

Most AI tools cannot tell you why.

Three failures stop AI from being usable in regulated professional work. None of them are model-quality problems, so no amount of model upgrade fixes them.

?

No provenance

An answer with no traceable source is unusable in regulated work. You cannot cite it, you cannot defend it, and you cannot tell whether the underlying authority was superseded last quarter.

!

No accountability

When the output is wrong, the audit asks who approved it. “The model” is not an answer a partner or a licensed entity can give to a regulator or a client.

~

No regression control

A prompt change on Tuesday silently degrades output on Wednesday, and nobody finds out until a client does. There is no gate, no baseline and no way back.

Three mechanics, enforced by the platform.

Not guidance in a prompt. These are compiler and runtime properties, held outside the model, where a prompt injection cannot reach them.

Evidence or abstention

Enforced

Every claim carries its sources, their authority and their dates. When retrieved evidence falls below the crew’s declared floor, the crew declines and names what is missing instead of guessing. Abstentions route to a knowledge-gap queue, not a failure log.

How evidence works →

Autonomy is earned

Measured

Every crew launches at 100% human review. It graduates to risk-weighted sampling only on measured accuracy at a published confidence bound, and reverts automatically on breach. Regulated outputs stay at full review permanently.

See the autonomy stages →

Nothing ships untested

Gated

Immutable Releases with locked dependencies, evaluation gates that block promotion, and a compiler that proves no untrusted input can reach an external action without an approval gate.

Inside the Runtime →

Design it. Reuse it. Run it.

Three surfaces, one lifecycle, one versioned artefact underneath all of them — the Crew Manifest.

ST

KrewOS Studio

Start from a proven Crew Template, configure it visually or describe the change in plain English. Every change becomes a versioned manifest with a visible diff before anything is applied. Studio →

HB

KrewOS Hub

A curated catalogue of verified Agents, Pods, Crew Templates and licensed Packs. Use, configure or fork — with lineage tracked and dependency versions locked. Hub →

RT

KrewOS Runtime

Durable execution that survives restarts, waits days for a human, never fires the same external action twice, and stops at your budget. Runtime →

Six crews already in production. Every one of them is a template.

These are not demos. They are wGrow’s own production systems, rebuilt on KrewOS and published as Crew Templates you can configure.

LawCrew
Jurisdiction routing, drafting, adversarial review and professional sign-off on document review.
Finance Close
Nested functional teams, reconciliation, exception handling and an approved workbook output.
AquaMind
Dynamic routing and an expert panel over farm telemetry, with safety gates and technical sign-off.
Content Studio
Long sequential production with retrieval, citations, bounded revision loops and bilingual output.
BizDev Intelligence
Parallel scouts, source verification, opportunity scoring and human promotion into CRM.
eCommerce Selection
Market and product research, scoring, creative generation and commercial approval.

The domain expertise ships with the platform.

A KrewOS Pack is a licensed vertical package — Crew Templates, Knowledge Packs, deterministic policies, evaluation datasets and dashboards, maintained and dated by the publisher. You are not starting with an empty canvas and a jurisdiction problem.

SG

Singapore Legal Practice

Jurisdiction routing, SG clause libraries, privilege handling, dated currency assertions.

FS

MAS Financial Compliance

Controls mapping, third-party and outsourcing policy packs, reconciliation evaluation sets.

AQ

Aquaculture Operations

Species and regional knowledge, water-chemistry rules, telemetry connectors, escalation routing.

TR

SG Tender Response

Relevance classification, requirement extraction, capability-library drafting, submission checks.

Browse the Packs catalogue →

Your compliance team will ask. Here are the answers, before they ask.

The Trust Centre is in the primary navigation, not the footer. Procurement should not have to email anyone to start an assessment.

Open the Trust Centre →

“We did not adopt this because it drafts well. We adopted it because when a client asks how a clause was reached, I can put the sources, the dates and the reviewer’s name in front of them in under a minute.”

Managing Partner, Singapore commercial practice · LawCrew Document Review, live since Q1

Measured outcome

Cost per matter reviewed
S$4.10
Reviewer minutes per matter
52 → 14
Evaluation pass rate
96.4%
Abstention rate
3.1%

Pass rate, last 12 releases

Read the full study →

Try it yourself

Self-serve

5,000 credits, 30 days, no card. Full Studio, Hub and Evaluation Lab in a development environment. You will have read a real evidence record inside twenty minutes.

Start free

Bring your compliance team

Sales-led

45 minutes with a solutions engineer, using your jurisdiction and your documents. We will walk the evidence panel, the audit export and the residency model with your risk owner in the room.

Book a demo
Platform overview

One platform from first draft to audited production.

KrewOS covers the whole lifecycle — assemble from verified components, test against evaluation suites, release immutably, run durably, and improve from the corrections your experts make anyway.

Four levels, one vocabulary.

The same four words are used in marketing, in the documentation, in the product and in the manifest schema. Vocabulary drift is how governance quietly stops meaning anything.

LevelDefinitionDeclaresReused as
AgentA single role with a typed input and output contract, a model profile and a permitted tool set.Inputs, outputs, tools, knowledge, cost bandA block in any Pod
PodA cooperating group of Agents with an internal coordination pattern — sequential, parallel, panel or router.Composed contract, internal topologyA collapsible node in any Crew
Crew TemplateA complete, runnable workflow for a business outcome, including human control points and declared effects.Outcome unit, evidence floor, approval gatesThe starting point for a project
KrewOS PackA licensed vertical bundle of Crew Templates, Knowledge Packs, deterministic policies, evaluation datasets and dashboards.Jurisdictions, currency date, update cadenceAn entitlement on your tenant

The manifest is the source of truth.

The canvas is an editor, not the source of truth. Visual edits, plain-English changes and Git commits all resolve into one versioned Crew Manifest that can be validated, diffed, exported, tested and deployed. This is what stops your AI system becoming a design file nobody can review.

>_

One artefact, three editors

Studio canvas, plain-English change plans and a Git repository are three views of the same manifest. None of them is privileged.

=/=

Diffable and reviewable

Every change produces a structured diff a reviewer can read, plus a validation result and a test run, before anything is applied.

# crew-manifest.yaml (extract)
apiVersion: krewos/v1
kind: CrewTemplate
metadata:
  name: lawcrew-document-review
  version: 4.2.0
  pack: sg-legal-practice@2026.02
outcome:
  unit: matter_reviewed
  baseline_minutes: 52
evidence:
  floor: 0.72
  on_insufficient: abstain_and_report
control:
  human_review: full   # regulated floor
  approver_role: qualified_professional
effects:
  reads: [matter_store, sg_statutes]
  writes: [draft_artefact]
  external: []          # no side effects declared

Three surfaces.

Build in Studio, reuse through the Hub, operate in the Runtime. Governance is common to all three rather than bolted onto one of them.

ST

Studio

Template-first assembly, typed ports that refuse invalid connections, plain-English change plans with diffs, and guardrails that fire before you can test. Explore Studio →

HB

Hub

A verified catalogue, not an open marketplace. Five verification tiers, fourteen classification dimensions and private tenant catalogues. Explore the Hub →

RT

Runtime

Durable runs, human wait states, idempotent actions, binding budgets, immutable releases and complete traces. Explore the Runtime →

Control Plane and Execution Plane.

Governance stays central; execution can move. That is how you get one governance model across the organisation and still satisfy a residency requirement that differs by entity.

Control Plane

Central
Identity & RBACHub catalogueManifests PoliciesEvaluation suitesReleases Audit indexBilling & credits

Execution Plane

Placeable
Compiled run planRun stateKnowledge indexes Model gateway callsTool and Action executionWorking artefacts
Compare the five deployment models →

What we deliberately do not do.

Published on purpose. A shorter list of honest limits builds more trust with a risk committee than a longer list of features.

01
We are not an unrestricted marketplace
Every published component is reviewed and verified against a stated bar. Anyone can publish into their own tenant catalogue; nobody publishes to the world unreviewed.
02
We do not build self-modifying production crews
Plain-English changes produce a change plan for a human to accept. A running release never rewrites itself.
03
We do not replace n8n, your ERP, CRM or data warehouse
We call them, under a permission and audit boundary. Rebuilding four hundred connectors is not our product.
04
We do not train foundation models
We govern access to approved ones. No customer data is used to train models, ours or a provider’s.
KrewOS Studio

Start from something that already works.

Template-first, never a blank canvas. Describe your outcome and KrewOS recommends a Crew Template matched to your industry, jurisdiction, language, risk level and required outputs — then shows you exactly what it would change.

Full Studio, Hub and Evaluation Lab on the trial. Development environment only.

The Template Wizard picks the starting point.

Recommendations are made against declared criteria, not vibes. The wizard shows why each candidate was ranked where it was, so a domain expert can overrule it with a reason.

CriterionWhat it selects onExample
IndustryClassification tags on the template and its PackLegal services → LawCrew Document Review
JurisdictionDeclared jurisdictional coverage and currency dateSingapore → SG Legal Practice Pack templates first
LanguageSupported input and output languagesEnglish + Simplified Chinese → Content Studio bilingual variant
Risk levelHuman-control level the template enforcesRegulated → only templates with a permanent full-review floor
Required outputsTyped output contract of the crewApproved workbook → Finance Close
Connectors availableDeclared connector dependencies against your registryNo CRM connected → BizDev Intelligence flagged, not hidden

Assemble Mode: the editor refuses bad structure.

Typed ports will not connect if the contracts do not match. Nested Pods collapse to one node so a twelve-agent crew stays readable. Risk, external side effects, missing permissions and estimated cost are visible on the node, not buried in a settings panel.

<>

Typed ports

Invalid connections are rejected at draw time with the contract mismatch named.

[+]

Collapsible Pods

A Pod is one node until you open it. Complexity stays in the manifest, not on screen.

/!\

Effect flags

Nodes that cause an external side effect are marked, and marked again if no approval gate precedes them.

S$

Cost estimate

Per-node credit estimates roll up to a per-run figure before you have run anything.

Describe the change. Review the diff. Then decide.

Plain-English changes never edit production. They produce a change plan, a visual diff, a validation result and a test run. You accept all, accept some, revise or reject.

You: add a second reviewer for matters over S$2m
      and require both to approve before release

Change plan — 3 changes, 0 breaking
+ node  approval.senior_partner  (human gate)
~ edit  approval.reviewer.policy
          quorum: 1 -> 2 when matter_value > 2000000
~ edit  release.gate.requires
          [reviewer] -> [reviewer, senior_partner]

Validation   12 checks passed, 0 failed
Test run     sample case SG-2291 · 2 gates hit · 41 credits
Effects      unchanged — no new external actions

  [ Accept all ]  [ Accept selected ]  [ Revise ]  [ Reject ]
Nothing in a change plan touches a deployed release. Applying a plan produces a new draft version that still has to pass the evaluation gate to be promoted.
ENG

Engineer Mode

The same crew as manifest, schemas, prompts, policies, Git status and generated project files. Edit here and the canvas follows.

Test Mode, before anyone else sees it.

IN

Sample inputs

Run against packaged sample cases or your own, step through node by node, and inspect the evidence each node retrieved.

VS

Version comparison

Run two versions over the same case set and compare outputs, evidence sufficiency, cost and gate outcomes side by side.

EV

Evaluation suites

Attach a suite and set the release gate threshold. Promotion is blocked until the suite passes at the declared bound.

Guardrails built into the editor

Blocks testing

These are caught before you can test, not after you deploy. Each one names the offending node and offers the standard remedy.

Unbounded loopsMissing exit pathsOrphan nodes Excessive permissionsSide effect without an approval gate Untyped portUndeclared external writeNo evidence floor set Knowledge pack past its freshness window
KrewOS Hub

A catalogue, not a marketplace.

Verified Agents, Pods, Crew Templates and Packs — classified across fourteen dimensions, versioned, dependency-locked and tested. Reuse is the point, and verification is what makes reuse safe.

Browsing is public. Using a component requires a workspace.

Agents
218
Single roles with typed contracts
Pods
74
Coordination patterns over Agents
Crew Templates
31
Complete runnable outcomes
Packs
4
Licensed vertical bundles

Verification tiers mean something specific.

A badge is worthless unless the bar behind it is published. Here is exactly what each tier required.

TierWhat it requiredUsable in production
DraftManifest validates and compiles. Nothing else.No
TestedPublisher-supplied evaluation suite present and passing at a declared threshold, with the dataset visible to entitled tenants.Development only
wGrow verifiedIndependent review of the manifest, effect declarations, permission scope, prompt-injection surface and evaluation methodology. Re-verified on every minor version.Yes
Tenant verifiedYour organisation’s own review process signed off by your named component owner. Scope and reviewer recorded.Yes, within your tenant
DeprecatedSuperseded or withdrawn. Existing pinned uses continue; new installs are blocked and owners are notified.Existing pins only

Use, configure or fork.

Three modes with different upgrade behaviour and different ownership. Compatible updates may be recommended, but they are never installed silently.

ModeWhat you getUpdatesWho owns correctness
UseThe published component at a pinned version, unmodified.Compatible updates recommended in your inbox; you choose when to move.The publisher
ConfigureThe same component with the publisher’s declared configuration surface set to your values.Same as Use. Your configuration is carried forward and revalidated.Publisher for behaviour, you for configuration
ForkA private copy you can change without limit, with lineage recorded back to the source.Upstream changes appear as a diff you may merge. Never automatic.You, from the moment of the fork

Classification is the search index.

Every component is classified on the same dimensions, which is why filtering across two hundred components is useful rather than exhausting.

IndustryJurisdictionLanguage Risk levelHuman control levelInput type Output typeConnector dependencyQuality status Model class requiredDeclared effectsEvidence floor Cost bandPublisher
PRV

Private tenant catalogues

Your own verified components stay yours. Publish to your organisation without publishing to the world, with the same verification workflow, the same classification and the same dependency locking.

LOK

Dependency locks

A Crew Template pins the exact versions of every Agent, Pod, Knowledge Pack and policy it depends on. A release is a checksummed closure, not a pointer to whatever is current.

KrewOS Runtime

Built for work that takes three days and cannot be run twice.

Professional work is not a request-response cycle. It waits for people, it touches systems that charge money, and it must be reconstructable months later. The Runtime is designed around those three facts.

DUR

Durable by default

Committed run state survives worker restarts, deployments and zone failures. A run waiting four days for a partner’s approval is a normal state, not a timeout.

1x

Idempotent Actions

Checkpoints before and after every externally visible effect, idempotency keys on every Action, and declared compensation behaviour. The same invoice is not sent twice.

S$

Budgets that bind

Soft limits degrade the model tier or concurrency first; hard limits fail closed before spending. Enforced per run, per project and per tenant.

Human wait states are first-class workflow nodes.

Approval, missing input, exception decision and escalation are states in the graph with owners, SLAs and reassignment — not an email and a hope.

Wait stateRaised whenResolves byIf the SLA expires
ApprovalA gate precedes a declared external effect, or the autonomy stage samples this run.A named approver accepts, rejects or edits.Escalates to the backup approver; the run stays parked, it does not proceed.
Missing inputA required typed input was not supplied or failed validation.Requester or operator supplies it.Reminder, then the case is returned to the requester.
Exception decisionA deterministic policy check failed and the policy allows a human override.An authorised role decides, with a mandatory reason.Escalates. Overrides are always recorded with the reason.
Specialist escalationEvidence fell below the floor and the crew abstained.A domain specialist supplies the missing source or answers directly.Routed to the knowledge-gap queue for the Pack owner.

Releases, rollback and in-flight cases.

Releases are immutable, checksummed and dependency-locked. The hard part is not rolling back — it is what happens to the six matters that were mid-review when you did.

What a Release pins

crew@4.2.0agent-set@sha256:9f1c…prompts@v18 policies@2026.02knowledge@sg-statutes-2026.01 model-profile@balanced-v3eval-suite@lawcrew-217

In-flight behaviour

Guaranteed

Long-running cases continue on the release they started on, even after you deploy a new one or roll back. A matter opened under 4.1.3 finishes under 4.1.3, and its audit record says so. New cases start on the current release.

Rollback is a promotion of an earlier immutable release, not a code revert. Because dependencies are locked, the earlier release behaves exactly as it did when it was current.

Every node run records what it actually used.

Not what the configuration said at some point. What this node, on this run, at this timestamp, resolved to.

CMP

Component version

Exact Agent or Pod version and its checksum.

MDL

Model profile

Provider, model, routing decision and fallback, if any fired.

PRM

Prompt version

The rendered prompt version, with variable bindings recorded.

KNW

Knowledge and tools

Knowledge Packs queried, chunks retrieved, tools called, policies evaluated.

Four deployment shapes

The same governed crew, invoked four ways. Governance is enforced by the runtime, never by the calling interface.

Authenticated APIWebhook or event handler ScheduleOperator-started case workflow
Governance & Evidence

Governance is the product, not a setting.

Five mechanics, enforced by the compiler and the runtime, outside the model prompt — where a prompt injection cannot reach them. Everything on this page is a product behaviour you can test on the trial, not a policy commitment in a PDF.

Sample Evidence Pack is a real export from a demonstration run, with client content replaced.

Mechanic 01
Evidence & abstention
Mechanic 02
Progressive autonomy
Mechanic 03
Declared effects
Mechanic 04
Correction flywheel
Mechanic 05
Audit & outcome economics
Mechanic 01

Evidence and abstention.

Every evidence set carries a sufficiency score against the specific claim it is asked to support. Each Crew Template declares an evidence floor. Below it, the crew returns a structured insufficiency result naming what could not be established and which sources would resolve it. It does not guess and then hedge.

GAP

Abstentions are not failures

An abstention means a missing source, not a broken crew. Abstentions route to a human knowledge-gap queue and are reported on their own line, separately from errors, so the two never get averaged together in a dashboard.

Conflicts are carried, not resolved

Where sources of comparable authority disagree, both positions are carried forward to the reviewer with their authority and dates. The system does not silently pick one and present it as settled.

EXP

Staleness propagates

When a source expires or materially changes, every artefact that relied on it is identified and its owners are notified. Freshness windows are declared per Knowledge Pack, and a run against stale knowledge is flagged on the artefact.

AUT

Authority is graded

Statute, regulation, published guidance, internal precedent and secondary commentary are not weighted the same. The grading is part of the Knowledge Pack, set by the publisher, and visible to the reviewer.

A real evidence record, annotated

Sufficiency 0.86 · floor 0.72
claim    "Notice period for termination without cause is 30 days
           unless the parties have agreed otherwise in writing."
node     drafting.clause_generator · run 8f21-4c · release 4.2.0

sources
  [1] Statute        · authority primary   · in force 2019-04-01  · weight 0.41
      s.12(3), cited verbatim, retrieved from sg-statutes-2026.01
  [2] Court judgment · authority primary   · 2023-11-14         · weight 0.28
      applied to a materially similar clause; distinguishing facts noted
  [3] Firm precedent · authority internal  · 2025-06-02         · weight 0.11
      matter 2025-0412, approved by a named partner
  [4] Commentary     · authority secondary · 2024-08-19         · weight 0.06
      supports, does not establish

conflict  none detected at comparable authority
staleness none — nearest freshness boundary 2026-04-01 (source [1])
decision  0.86 ≥ 0.72 → proceed, sources attached to the artefact

Had the score come in at 0.64, the run would have produced an insufficiency result reading: cannot establish notice period for a fixed-term contract under s.12(3); resolve with the 2024 amendment commencement notice or a firm precedent post-2024.
Mechanic 02

Progressive autonomy.

Binary approval caps throughput at human speed forever. Unlimited autonomy is not acceptable in regulated work. KrewOS makes autonomy something a crew earns against measured evidence, and loses automatically when the evidence stops supporting it.

StageEntry conditionReview rateReverts when
Full reviewDefault for every new crew and every new release of a crew. No exceptions, no override.100% of outputs— this is the floor
Supervised sampling≥ 200 reviewed outcomes and measured accuracy at or above the declared bound, at 95% confidence, over a rolling window.25–40%, risk-weightedAccuracy drops below the bound, a severity-1 correction is recorded, or the release changes.
Extended samplingSustained performance at supervised sampling over two further windows with no severity-1 corrections.5–15%, risk-weightedAny breach reverts one stage immediately and notifies the crew owner and the compliance role.
Regulated floorApplied to any output class the tenant marks as regulated, or that the Pack marks as requiring a qualified professional.100%, permanentlyNever graduates. Sampling cannot be enabled on this class.
RSK

Sampling is risk-weighted

Never uniform. Sampling probability rises with matter value, novelty against the evaluation corpus, evidence sufficiency close to the floor, and any deterministic check that came back marginal.

REV

Reviewers are measured too

A sampling regime is only as sound as the reviews that calibrate it. Review latency, edit rate, agreement with peer reviewers and blind re-review performance are all tracked and reported.

Reversion is automatic

Reversion is a runtime action, not a recommendation. It fires without a human in the loop, and the reversion event is itself an audit record with the triggering measurement attached.

Mechanic 03

Declared effects, verified at compile time.

Every component declares what it reads, writes, spends and causes externally. The compiler statically proves those properties before a release exists — including that no path runs from untrusted input to an external side effect without an intervening approval gate.

DeclarationProved at compile timeEnforced at run time
ReadsEvery read target is in the declared set and the component has the permission.Reads outside the set are refused and recorded.
WritesNo write to a target the component did not declare.Undeclared writes fail the run rather than the check.
SpendWorst-case cost is computable and within the project ceiling.Soft limits degrade; hard limits fail closed before spending.
External effectsNo taint path from untrusted input to an external effect without an approval gate on it.Idempotency key required; compensation behaviour declared; approval enforced by the runtime.
This is a proof, not a policy document. If the property does not hold, there is no release to deploy. There is no flag to disable the check and no role that can waive it.
The proof covers declared effects. It does not make a model’s judgement correct — that is what evidence floors, evaluation gates and human approval are for.
$ krewos compile crew/lawcrew-document-review
  resolving dependencies      ok   41 components, 41 pinned
  typing ports                ok   118 edges checked
  effect declarations         ok   3 external effects declared
  taint analysis              ok   untrusted -> external: 3 paths, 3 gated
  budget bound                ok   worst case 812 credits ≤ ceiling 1,500
  evaluation gate             ok   lawcrew-217 · 96.4% ≥ 95.0% threshold
release 4.2.0 sealed  sha256:c41b9e7a…  immutable
Mechanic 04

Human accountability and the correction flywheel.

Every approval, rejection and edit is an immutable Correction Record tied to a named reviewer, a run, a release and a component version. Human decisions are append-only; corrections supersede, they never rewrite.

What a Correction Record holds

Reviewer identity and role
Named, authenticated
Decision
Approve / reject / edit
Reason
Mandatory on reject and edit
Run, release, component version
All three, pinned
Evidence set at decision time
Snapshotted
Before and after text
Full diff retained
Timestamp and duration
Immutable
Supersedes
Prior record id, if any

The flywheel

Compounds
1
An expert disagrees with an output
They edit it in the approval workbench, with a reason. That is work they were going to do anyway.
2
The correction is confirmed
A second qualified reviewer confirms the correction is generalisable, not case-specific.
3
It is promoted into the evaluation suite
As a case with an expected outcome, attributed to the reviewer who found it.
4
The gate gets harder
The next release must pass the case to be promoted. Your suite grows out of real disputed cases from your own work.
This is why the evaluation suite is the durable asset and why a competitor cannot copy it. The model is a commodity; two hundred disputed cases from your own practice, with expert-confirmed expected outcomes, are not.
Mechanic 05

Audit and outcome economics, from the same records.

End-to-end traces from run to node to model call to retrieval to tool to approval, exportable in machine-readable form. The figures that enforce your budgets are the same figures that report your cost per outcome, so they cannot disagree.

Cost per outcome
S$4.10 / matter
Platform and model credits, fully attributed
Human minutes displaced
38 / matter
Against your configured baseline of 52
Unattributed spend
0 credits
Every credit maps to a run, node and outcome

What an audit export contains

JSON · CSV · signed PDF
Run identity and timelineRelease and component versions Model profiles and routing decisionsEvery retrieval with source and score Evidence sets per claimPolicy evaluations and outcomes Tool and Action calls with idempotency keysHuman decisions with identity and timestamp Abstentions and their resolutionsCost records per node Autonomy stage and sampling decision

Exports are scoped by matter, by date range or by crew, produced by an authorised role, and the act of exporting is itself an audit record. Retention is configured by your organisation, and records are immutable for the configured period.

UNI

Every crew declares its outcome unit

A matter reviewed, a reconciliation closed, an article published, a pond advisory issued. Cost and time are reported against that unit, not against tokens, which no partner has ever wanted to discuss.

BSL

Baselines are yours, not ours

You configure the manual baseline the displacement figure is measured against. We will not publish a number derived from a baseline we invented.

For the risk gatekeeper

Control mapping, retention, deletion, subprocessors, incident process and the pre-answered questionnaire pack.

For compliance & risk →

For the technical evaluator

Manifest schema, the compiler’s guarantees, the audit event model and the export API.

Governance documentation →
Deployment & Residency

Central governance. Your choice of where it runs.

One governance model across the organisation, and data that stays where your regulator, your client agreements or your board require it to stay. These are not in tension, because the two planes are separable.

The plane split, without the architecture diagram.

The Control Plane holds identity, catalogue, manifests, policies, evaluations and releases. The Execution Plane runs the compiled plan and holds run state. They can live in different places. That is what lets you keep one governance model and still keep your data where it must stay.

Stays central, always

Control Plane
User identity and role assignmentsHub catalogue metadata Crew Manifests and versionsPolicy definitions Evaluation suite definitionsRelease records and checksums Credit ledgerAudit index (pointers, not payloads)

Moves with your deployment model

Execution Plane
Case and matter contentKnowledge Pack indexes and chunks Run state and checkpointsRetrieved evidence text Generated artefacts and draftsModel gateway request payloads Tool and Action payloadsAudit record payloads

Five deployment models.

The same manifests, the same compiler, the same audit model in every one. What changes is where execution happens and who operates the infrastructure.

ModelWhere execution runsOperated byTypical buyer
KrewOS CloudManaged, shared, Singapore regionwGrowSME and standard enterprise
KrewOS Cloud DedicatedManaged, dedicated compute and storagewGrowHigher isolation or performance needs
Enterprise — Customer VPCYour cloud account, your networkJointly, under a runbookResidency and private-system access
Enterprise — HybridCentral control, local runtime and knowledgeJointlyPrivate data with managed governance
Enterprise — Private / LocalYour infrastructure, air-gap capableYou, with supportRestricted or disconnected environments

Residency commitments.

Stated precisely, because a vague residency claim is worse than none — it fails the first time procurement reads it carefully.

SG

Singapore is the default region

The workspace region is chosen at workspace creation and is immutable for that workspace. Moving regions means creating a new workspace and migrating, which we will help with but will not pretend is a toggle.

MDL

Model calls are constrained by policy

Every model profile declares its approved provider jurisdictions and the provider’s retention terms. A crew cannot route to a provider outside the profile’s approved set, and the routing decision is recorded on the run.

KEY

Customer-managed keys

Available on Cloud Dedicated and all Enterprise models. Not available on shared Cloud. We state which tiers rather than implying it is universal.

BYO

BYOK and private model adapters

Use your own provider contracts, or connect a self-hosted or regionally-hosted model behind the same model-profile policy, evidence and audit machinery.

CapabilityCloudCloud DedicatedCustomer VPCHybridPrivate
Singapore-region executionYesYesYour regionYour regionYour site
Customer-managed keysNoYesYesYesYes
Private network access to your systemsNoPeeringNativeNativeNative
BYOK model credentialsYesYesYesYesRequired
Disconnected operationNoNoPartialPartialYes
Central governance across entitiesYesYesYesYesScheduled sync
Integrations

Governed at the edges, open in the middle.

KrewOS is not trying to become your integration layer. It calls the systems you already run, and exposes governed crews to the assistants and workflow tools your teams already use — with policy, evidence and approval enforced by the runtime rather than by the caller.

Model Context Protocol, in both directions.

KrewOS as an MCP server

Outbound

Your deployed crews are callable as standard tools by external assistants. Governance travels with the crew: the evidence floor, approval gates, budget ceilings and audit recording are enforced by the runtime, never by the calling interface. An assistant cannot ask a crew to skip its approval gate, because the gate is not part of the interface it can see.

KrewOS as an MCP client

Inbound

Approved external MCP servers are consumable as Tools under the same registry, permission and audit controls as any first-party Tool. Administrators can withhold individual tools from a server while admitting the rest — a server is not an all-or-nothing trust decision.

 ToolsActions
What they doRead or compute. No externally visible change.Cause an external side effect — send, post, write, pay, publish.
Idempotency keyNot requiredRequired
Compensation behaviourNot applicableMust be declared
Approval gateOptionalRequired where configured, and required by the compiler on any untrusted-input path.
CheckpointingOn node boundaryBefore and after the effect
Replay behaviourRe-executed freelyNever re-executed; the recorded result is reused

n8n is a first-class adapter, not a competitor.

A crew can call a governed n8n workflow as an Action, and n8n can start a deployed crew through an authenticated API or an event. We are not rebuilding four hundred connectors, and you should be suspicious of anyone who says they have.

n8n

Crew calls n8n

Registered as an Action with an idempotency key and declared compensation. The workflow’s effect declaration is part of the crew’s compiled proof.

API

n8n calls the crew

Authenticated API or event trigger. The crew still runs its gates, and the n8n caller waits or receives a webhook when the human step completes.

DB

Direct integrations

REST, webhooks and read-only database connectors where a workflow tool would just be a hop. All under the same permission registry.

Bring your own key.

Platform-managed or tenant-managed credentials, held as encrypted secret references and injected at call time by the gateway.

Keys never appear in prompts, logs, manifests, exports, error messages or support tooling. A support engineer with full impersonation cannot read a tenant key, because the plaintext is never in a surface impersonation can reach. Model profiles declare which credential set they may use, so a crew cannot silently fall back to a platform key when your key rate-limits — it fails, or degrades to a declared fallback profile you approved.

anthropicopenaigoogle-vertex azure-openaiaws-bedrockself-hosted-openai-compatible
Under BYOK, model consumption is billed by your provider directly and your KrewOS credits cover only platform runtime. Two meters, one wallet — and the second meter reads zero. How credits work →
GIT

Git, Claude Code and Codex

Export an engineering-ready repository — manifest, components, schemas, prompts, policies, evaluations, tests, deployment files and agent instruction files. Linked projects round-trip through a diff and approval workflow; ejected projects are yours outright. For engineering →

SSO

Identity

OIDC and SAML single sign-on with enforced MFA and role mapping from your IdP groups. SCIM user provisioning is on the roadmap and is not shipped today; we will not list it as available until it is. Security details →

Why not a generic agent builder

You can build a crew in a weekend. Getting it past your risk committee is the other eleven months.

Generic agent frameworks and workflow tools are good products. This page is about which category of problem each one is actually shaped for, and where the boundary sits.

We compare capability categories, not named vendors. The frameworks are open source; you can verify every row yourself.

An honest capability comparison.

“You build it” is not a criticism. A framework that shipped opinionated governance would be a worse framework. It is simply a description of who does the work and who carries the risk if it is not done.

CapabilityGeneric agent frameworkWorkflow tool + LLM nodesKrewOS
Orchestrate multiple agentsYesPartlyYes
Typed contracts between componentsYou build itNoEnforced
Evidence with provenance and sufficiency scoringYou build itNoBuilt in
Abstain below a declared evidence floorYou build itNoBuilt in
Compile-time proof that untrusted input cannot trigger a side effectNoNoBuilt in
Immutable releases with dependency lock and evaluation gatesYou build itNoBuilt in
Human approval as a durable workflow stateYou build itPartlyBuilt in
Risk-weighted review sampling with automatic reversionNoNoBuilt in
Effect verification — idempotency, compensation, no duplicate sendsYou build itPartlyBuilt in
Audit export a regulator would acceptYou build itPartlyBuilt in
Cost per business outcome, fully attributedYou build itNoBuilt in
Licensed jurisdictional domain assetsNoNoPacks
Data residency with a control / execution plane splitYou build itSelf-hostSupported
Freedom to walk away with your workTotalTotalGit export & eject

What you would have to build yourself.

Every row above marked “you build it” is a real system with a real maintenance cost. Enumerated honestly, this is what sits between a working prototype and a crew a risk committee will sign off.

01
Manifest schema and a compiler
A canonical machine-readable definition, plus static checks: type resolution across ports, taint analysis from untrusted input to external effects, worst-case budget bounds.
~3 months
02
Evaluation harness with release gating
Dataset management, scorers, confidence bounds, regression detection, and a promotion gate wired into deployment.
~2 months
03
Evidence model
Provenance capture, authority grading, sufficiency scoring against a claim, conflict detection, freshness windows and staleness propagation to dependent artefacts.
~3 months
04
Approval workbench
Queues, routing, SLAs, delegation, immutable correction records, reviewer measurement, and a mobile-tolerable review surface.
~2 months
05
Secrets and permission gateway
Credential injection outside the prompt, per-component permission scoping, and a guarantee that keys never reach logs, exports or support tooling.
~1.5 months
06
Durability, idempotency and compensation
Checkpointing, replay semantics, idempotency keys, compensating actions and multi-day wait states that survive a deploy.
~3 months
07
Cost attribution and outcome accounting
Per-node metering, budget enforcement that binds before spend, and reconciliation to a business outcome unit with zero unattributed spend.
~1.5 months
08
Audit export and release management
Immutable records, retention policy, scoped export, signing, plus immutable releases with dependency locks and in-flight case continuity.
~2 months
That is roughly eighteen months of a competent team, and then it is yours to maintain forever. It is also not your product. The question is not whether your engineers could build it — they could. It is whether the firm wants to own a governance platform as well as a practice.

When not to use KrewOS.

If your problem is on this list, we will tell you on the call rather than after the pilot.

1x

A single-step task

Summarise this, classify that, extract these fields. Call the model API directly. Governance machinery around one call is overhead with no offsetting benefit.

A-B

Deterministic integration

Move a record from A to B on a schedule with no judgement involved. Use a workflow tool. There is no evidence to trace and no decision to attribute.

CHT

Consumer-facing chat

High volume, low regulatory exposure, cost per interaction is the binding constraint. Use something cheaper. Our per-run cost carries governance you do not need.

LAB

Research prototyping

You want zero structure and maximum freedom to change everything hourly. Use a framework. Typed ports and release gates are friction you have not earned yet.

“We prototyped on a framework in three weeks and it was genuinely good. Then compliance asked for the evidence trail, the approval record and the regression gate, and we were looking at a year of platform work that had nothing to do with our practice.”

Head of Technology, regional professional services group

Book a technical review

90 minutes with a solutions engineer and your architect. Bring your existing prototype. We will map it onto the manifest model, name what is missing for your risk committee, and tell you honestly if the answer is that you do not need us.

Book a technical review
Interactive demo · no signup

Watch a governed run, end to end.

A complete replay of a real LawCrew Document Review run: the graph as it executed, the evidence behind one contested clause, the approval task a partner saw, and the audit export that came out of it. Nothing is gated and nothing is asked of you.

Replay takes about four minutes. Client content has been replaced; the structure, timings and costs are real.

Run 8f21-4c · LawCrew Document Review

Completed
release 4.2.02h 41m elapsed
01
Jurisdiction router
Governing law identified as Singapore from the choice-of-law clause. Routed to the SG Legal Practice Pack template variant.
1.2s
02
Evidence Research Pod
Four agents in parallel over statutes, judgments, firm precedent and commentary. 41 chunks retrieved, 12 admitted above the authority threshold.
38s
03
Drafting
Nine clauses generated, each with its evidence set and sufficiency score attached to the artefact.
1m 04s
04
Adversarial reviewer
Argued against each clause from the counterparty position. Two clauses returned for revision; one revision loop, bounded at three.
2 returned
05
Regulatory Review Pod
Deterministic checks, not model judgement. 14 passed, 1 marginal — the marginal check raised the sampling weight for this matter.
1 marginal
06
Abstention on clause 7
Sufficiency 0.64 against a floor of 0.72. Structured insufficiency result issued naming the missing commencement notice. Routed to the knowledge-gap queue.
Abstained
07
Professional approval
Waited 2h 33m. Approved with two edits by a named qualified professional; both edits recorded as Correction Records with reasons.
Human
08
Release of the artefact
Draft released to the matter store. No external side effect declared, so no idempotency key required.
Done

What most demos skip.

This replay deliberately includes the awkward parts, because they are the parts that decide whether the product is real.

ABS

An actual abstention

Clause 7 could not be established. You will see the insufficiency result, the named missing source and the queue it went to — not a confident paragraph with a hedge in it.

EDT

A human overruling the crew

The approving partner changed two clauses. You will see the diff, the reason, and how those corrections became evaluation cases for the next release.

S$

The bill

Platform and model credits itemised by node, the SGD equivalent, and what the same run costs under BYOK. How credits work →

Run this yourself in 20 minutes

The trial ships with the same sample matter. Sign up, pick the template, run the case, read the evidence, approve the task and open the audit trail. It costs about 40 of your 5,000 credits.

Start free Quickstart

See it with your own documents

45 minutes with a solutions engineer, using your jurisdiction, your document types and your review policy. Bring your compliance lead; the second half of the session is the audit export.

Book a demo
Solutions

Governed crews, shaped to the work you actually do.

Four industries where the evidence has to hold up, and three roles who each need a different question answered before anyone signs anything. Start wherever you sit.

By industry.

Each industry page names the production crew, the licensed Pack behind it, the controls that matter to that buyer, and measured numbers from a live deployment.

Legal services

Regulated floor

Document review your firm can sign. Jurisdiction routing, adversarial review, deterministic risk checks and permanent professional approval, with every clause traceable to its source.

LawCrew Document ReviewSingapore Legal Practice Pack
Legal services →

Financial services

Dual approval

A close you can hand to the auditor. Nested functional teams over reconciliation and exception handling, with every figure reconciling to its evidence and every exception carrying a named decision.

Finance CloseMAS Financial Compliance Pack
Financial services →

Aquaculture

Safety gated

Advice a farm manager can act on at 5am. Dynamic routing to specialists, an expert panel where the answer is contested, telemetry verification, and escalation when the evidence will not support a recommendation.

AquaMind AdvisoryAquaculture Operations Pack
Aquaculture →

Professional services & content

Self-serve

Production volume without losing the byline. Long-form production with citations, bilingual output, bounded revision loops, senior editor approval, and governed publishing into your CMS.

Content StudioBizDev IntelligenceSG Tender Response Pack
Professional services →
eCommerce and retail — product scoring, creative grading and commercial approval on the eCommerce Selection crew — is in production at wGrow and will get its own page. Ask for it on a demo in the meantime.

By role.

The same platform, three completely different first questions. We have stopped pretending one page answers all of them.

ENG

For engineering

Manifest-first, Git-native, ejectable. What we own so you do not, the extension contract, sandbox rules, and a quickstart on the page rather than a link to one. For engineering →

GRC

For compliance & risk

Everything your questionnaire asks, in one place. Control summary, what an audit export actually contains, how the platform behaves when it does not know, and the document pack. For compliance →

OPS

For operations

The approval queue, SLAs and reassignment, incident handling, the run monitor and how to staff a review rota. Page in progress — ask for the walkthrough. Book a walkthrough →

Not sure where you fit?

Estimate the spend

Pack, volume and review posture in, credits per month, SGD and payback out.

Open the estimator →

Watch a real run

Four minutes, no signup, including the abstention and the human overruling the crew.

Interactive demo →

Read a case study

Situation, crew design, controls, measured numbers, and the part that did not work.

Case studies →
Solutions · Financial services

A close you can hand to the auditor.

Finance Close runs nested functional teams over reconciliation and exception handling, producing structured workbooks and reports where every figure reconciles to its evidence and every exception carries a named decision with a reason.

The workflow.

Nested Pods per functional area, running in parallel where they are independent and sequencing where they are not, with exceptions routed rather than swallowed.

01
Ingest and normalise
Ledger extracts, bank statements, subledger feeds and supporting schedules, typed and validated on entry. Anything that fails validation becomes a missing-input wait state, not a silent gap.
02
Reconciliation Pods
One Pod per area — cash, receivables, payables, accruals, intercompany, fixed assets. Arithmetic is performed by deterministic nodes, never by the model.
Deterministic
03
Exception classification
Breaks are classified by cause and materiality, with the supporting evidence attached. Immaterial and explained breaks are cleared with a record; the rest are routed.
04
Exception decisions
Each routed break becomes an exception-decision wait state owned by a named person with an SLA. Overrides require a mandatory reason.
Human
05
Dual approval
Configured high-risk actions require two distinct approvers with segregation of duties enforced by the runtime, not by convention.
Two approvers
06
Workbook and report artefacts
A structured workbook where every figure carries a link to its reconciliation and its evidence, plus a narrative report drafted from the same records.
Model arithmetic is not used anywhere in this crew. Calculations run in deterministic nodes with the inputs, the formula version and the result recorded. The model reads, classifies, explains and drafts; it does not add up.

Controls the CFO asks about.

ControlHow it is enforcedEvidence produced
Segregation of dutiesApprover roles are distinct from preparer roles; the runtime refuses a second approval from the same identity.Both approver identities on the record
Dual approval on high-risk actionsConfigured per action class and per threshold; enforced as a workflow state, not a UI convention.Two Correction Records, both timestamped
Calculation verificationDeterministic nodes with versioned formulas. Model output is never used as a figure.Inputs, formula version, result
Budget enforcementHard limits fail closed before spend, per run and per project.Budget decision recorded on the run
No duplicate external actionsIdempotency keys on every Action, with declared compensation behaviour.Key and outcome per action call
Complete cost attributionEvery credit maps to a run, node and outcome unit. Unattributed spend is structurally impossible.Per-node cost records
Immutable auditAppend-only records with configured retention; export is itself an audited event.Signed export, scoped by period

MAS Financial Compliance Pack.

Controls mapping, policy packs covering third-party and outsourcing considerations, reconciliation evaluation datasets and reporting dashboards — maintained with a dated currency assertion and a published update cadence.

MAP

Control mapping

Platform controls mapped against technology risk and outsourcing expectations, with the gaps stated rather than omitted.

POL

Deterministic policy packs

Materiality thresholds, approval matrices and prohibited-action rules expressed as policy, versioned and evaluated outside the prompt.

EVL

Evaluation datasets

Reconciliation and exception cases with expected outcomes, used as the release gate. Extended by your own disputed cases over time.

DSH

Dashboards

Close progress, exception ageing, approval latency, cost per close and reviewer agreement, from the same records that drive the audit.

KrewOS is not certified, licensed or endorsed by the Monetary Authority of Singapore or any other regulator. Regulatory obligations remain those of the licensed entity. Read the sector alignment page →

Ask for the controls mapping and the pre-answered questionnaire pack before you book anything.

Request the security pack →
Close cycle
6 days from 11
Group of four entities
Exceptions auto-cleared
61%
With evidence, not by suppression
Cost per close
S$182
All entities, platform + model
Unattributed spend
0
Structural, not a target
Solutions · Aquaculture

Advice a farm manager can act on at 5am.

AquaMind routes an operational question to the right specialists, convenes an expert panel where the answer is contested, checks it against farm telemetry and safety rules, and escalates to a technical specialist when the evidence will not support a recommendation.

The workflow.

Routing is dynamic because the question is not known in advance. A question about mortality after a storm and a question about feed conversion go to different specialists and hit different gates.

01
Dynamic routing
02
Expert advisory panel
03
Evidence verification
04
Safety gate
05
Telemetry check
06
Technical sign-off
PNL

The panel disagrees on purpose

Where nutrition, water chemistry and pathology would give different answers, all three are convened and their disagreement is surfaced to the reader with each position’s supporting evidence. The crew does not average three specialists into one bland paragraph.

SAF

Safety gate is deterministic

Dosage ranges, withdrawal periods, species tolerances and prohibited treatments are coded rules evaluated outside the model. A recommendation that violates one is blocked, not softened.

TEL

Checked against the pond

Recommendations are validated against current telemetry — dissolved oxygen, temperature, salinity, stocking density, recent feed and treatment history. Advice inconsistent with the readings is flagged before it reaches anyone.

Why abstention matters most here.

A confident wrong answer about water chemistry kills a pond overnight. There is no review queue at 5am and no partner to catch it.

An abstention, as the farm manager sees it

Insufficient evidence
question  "Mortality up 4x in pond 7 overnight after heavy rain.
           Treat now or wait?"

I cannot establish a treatment recommendation.

what is missing
  · dissolved oxygen reading for pond 7 after 02:00
    (last reading 19:40 yesterday, before the rainfall)
  · salinity after the freshwater inflow

what would resolve it
  · a DO reading now — if below 3.5 mg/L this is
    consistent with post-rain stratification, not disease
  · a salinity reading at 1m depth

what I can say now
  · the mortality pattern is not consistent with the two
    pathogens seen in this region this season
  · do not treat until DO is ruled out — aeration first

escalated to  technical specialist on call · SLA 30 min
That is a feature the farm manager will thank you for. It names the two readings, explains what each would mean, gives the one safe action available now, and puts a human on it.
ESC

Escalation is a workflow state

Not a suggestion to call someone. The specialist gets the case with the question, the telemetry, the panel positions and the reason for abstention already assembled.

Aquaculture Operations Pack.

SPC

Species & regional knowledge

Knowledge Packs per species and growing region, with dated currency and freshness windows on seasonal guidance.

H2O

Water-chemistry policy rules

Deterministic tolerance ranges and interaction rules, versioned, evaluated outside the model.

IOT

Telemetry connectors

Read-only connectors to common pond sensor platforms, with staleness on a reading treated as missing evidence.

INC

Evaluation cases from real incidents

Including the ones where the original human call was wrong. Those are the cases worth gating on.

2x

Bilingual output

English and Simplified Chinese, generated from the same evidence set rather than translated afterwards, so both versions cite the same sources.

PHN

Mobile-first approval

The technical sign-off is designed to be decidable on a phone, standing at a pond, in daylight.

OFF

Intermittent connectivity

Runs are durable. A question asked when the link drops completes when it returns; nothing is lost and nothing is silently retried into a duplicate.

Solutions · Professional services & content

Production volume without losing the byline.

Agencies, consultancies and in-house teams publishing under their own name. Same governance, lower regulatory weight, and a trial you can be productive in this afternoon.

This is the fastest path from signup to a governed run. No connectors required to get value.

Three crews, in production at wGrow.

We run our own content, pipeline and tender work on these. The numbers on this page are ours, which is why we can publish them without asking a client.

Content Studio

Sequential

Long sequential production: research with citations, bilingual English and Simplified Chinese drafting, compliance gates, revision loops bounded at three iterations, senior editor approval, then a governed publishing Action into your CMS through n8n.

BizDev Intelligence

Parallel

Parallel scouts on a schedule, aggregation, source verification, opportunity scoring against your criteria, then human promotion and a governed CRM Action. Nothing enters your pipeline without a person promoting it.

SG Tender Response

Pack

Singapore tender relevance classification, requirement extraction, response drafting against your capability library, a compliance checklist against the tender’s own conditions, and submission approval.

CIT

Citations survive the draft

Claims keep their sources through revision loops. When an editor cuts a paragraph, the sources that supported only that paragraph are released; the rest stay attached.

3x

Revision loops are bounded

Three iterations, then it goes to a human regardless. Unbounded self-critique burns credits and converges on nothing; the editor makes a better call in ninety seconds.

PUB

Publishing is an Action

Which means an idempotency key, declared compensation and an approval gate. The crew cannot publish twice, and it cannot publish at all without the editor.

A day in the queue.

What the senior editor actually does, and how long it takes. If this is unpleasant, nothing else on the site matters.

AM
09:10 — six drafts waiting
Each with its brief, its evidence set, the compliance gate result and the two things the adversarial pass flagged. Sorted by deadline, then by risk weight.
6 tasks
OK
09:12 — four approved
Read, spot-checked against two citations each, approved. Roughly 90 seconds per piece.
Approved
ED
09:19 — one edited
Tone was wrong for the audience. Edited in place with a reason; the correction is queued for confirmation as an evaluation case.
Edited
AB
09:24 — one abstained
The crew could not source a market-size claim in the brief. It said so and named what would resolve it, rather than inventing a plausible figure.
Abstained
PM
Later — the flywheel
The morning’s edit, once confirmed by a second editor, becomes a case in the evaluation suite. The next release has to pass it.
Pieces / month
140
Two editors, both part-time on this
Editor minutes / piece
6 from 45
Includes the rejected ones
Cost per published piece
S$2.35
S$0.71 under BYOK
Abstention rate
4.8%
Mostly unsourceable claims in briefs

Start this afternoon

Content Studio is the lowest-risk, fastest template on the platform and needs no connectors to be useful. Sample corpus included. First governed run in under twenty minutes.

Start free Quickstart

Bilingual from the start

English and Simplified Chinese are generated from one evidence set, not translated after the fact, so both versions cite the same sources and pass the same compliance gate. Other ASEAN languages on request.

Browse the Packs →
For engineering

Manifest-first. Git-native. Ejectable.

If you are the person who will be blamed when this is unmaintainable in eighteen months, this page is for you. The short version: the canonical artefact is a file, it lives in your repository if you want it to, and you can leave with everything.

You are not trapped.

Export a complete engineering repository at any time. Not a JSON blob — a project that builds, tests and deploys.

$ krewos export --project lawcrew-doc-review --mode eject

lawcrew-doc-review/
  crew-manifest.yaml        # canonical source of truth
  components/               # agents, pods, deterministic nodes
  schemas/                  # typed port contracts
  prompts/                  # versioned, with bindings
  policies/                 # deterministic rules
  evaluations/              # suites, datasets, scorers
  tests/                    # unit + integration
  extensions/               # your custom tools and actions
  deploy/                   # container + IaC
  AGENTS.md  CLAUDE.md      # agent instructions
  README.md

ejected  this project is yours. runtime APIs continue to work.
<->

Linked projects round-trip

Keep the project linked and changes flow both ways through a reviewed diff. A Studio edit appears as a proposed commit; a commit appears as a change plan a reviewer accepts or rejects. No silent overwrite in either direction.

OUT

Ejected projects are yours

Full stop. No licence revocation clause on your manifests, no phone-home requirement, and the deployed runtime APIs keep working. Packs are separately licensed and that licence is what ends — not your code.

CLI

Everything is scriptable

Validate, test, package, deploy and inspect from the CLI. The web Studio calls the same API surface you do; there is no privileged path.

API

Eleven API domains

Runs, approvals, releases, components, knowledge, evaluations, audit, cost, secrets, identity and webhooks. OpenAPI spec published, with a downloadable collection.

The manifest schema is published and versioned. If you want to generate manifests from your own tooling and never open Studio, that is a supported way to use the product, not a workaround.

What we own so you do not.

Each of these is a system you would otherwise build, staff and carry. The full build-versus-buy breakdown →

DUR

Durable state and checkpointing

Runs that survive worker restarts and deploys, with replay semantics you do not have to reason about.

1x

Idempotency and compensation

Keys, retries and declared compensating actions on every externally visible effect.

KEY

Secret injection

Credentials injected at call time by the gateway, never present in prompts, logs, manifests or exports.

PRM

Permission enforcement outside the prompt

A component cannot talk its way into a permission it was not granted, because the grant is not in the context window.

S$

Cost attribution

Per-node metering that reconciles to a business outcome unit with no unattributed spend.

EVL

Evaluation harness and audit trail

Datasets, scorers, confidence bounds, release gating, and an immutable exportable trace.

Extension contract and sandbox rules.

Stated plainly, because engineers respect a clear boundary more than a generous one.

You can writeAgainstAppears in Studio as
Custom ToolsPublished Tool interface — typed input and output, no external side effect.A block, with its contract shown on the node
Custom ActionsAction interface — must supply an idempotency key and declare compensation behaviour.A block flagged as effect-causing
Deterministic nodesPure function interface. No model call, fully replayable.A block the compiler can reason about
ScorersEvaluation scorer interface — case in, score and rationale out.An option in the Evaluation Lab
ConnectorsConnector interface with a declared permission scope and read/write classification.An entry in your Tools registry
BOX

Sandboxed execution

Generated and custom code runs sandboxed with network and filesystem restrictions declared per component. Nothing runs with ambient credentials.

SCN

Dependency scanning

Every dependency is scanned on registration and on a schedule. A new critical advisory on a registered component notifies its owner and blocks new releases that include it.

REV

Review before registration

Custom components are reviewed before they are registered in a tenant catalogue, by your reviewers under your bar. The workflow is the same one the Hub uses.

Quickstart, on this page.

Twenty minutes from nothing to a governed run with a readable evidence record.

# 1. install and authenticate
$ npm i -g @krewos/cli
$ krewos auth login                      # opens browser, stores a scoped token

# 2. start from a template rather than a blank canvas
$ krewos init --template content-studio --name first-crew
  resolved  content-studio@2.4.1  · 11 components  · pinned

# 3. attach the sample corpus and validate
$ krewos knowledge add ./samples/corpus --pack sample-corpus
$ krewos validate
  schema ok  ·  ports ok  ·  effects ok  ·  budget ok

# 4. run a sample case in the development environment
$ krewos run --case ./samples/brief-01.json --watch
  research    done   8 sources, sufficiency 0.81  (floor 0.70)
  draft       done   1,140 words, 8 claims cited
  compliance  done   6 checks passed
  approval    waiting  task assigned to you

# 5. approve, then read the trace
$ krewos approve --task t-7741 --note "tone fine, sources check out"
$ krewos trace --run r-8f21 --format json > trace.json
  42 events  ·  cost 38 credits (S$0.38)  ·  0 unattributed
For compliance & risk

Everything your questionnaire asks, in one place.

You have been sent here by a colleague who wants to buy this. Here is the control summary, what an audit export actually contains, how the platform behaves when it does not know, and the document pack — without a call.

The document portal is click-through NDA gated. Everything on this page is not.

Control summary.

Scannable, because you have eleven of these to get through this week. Each row links into the Trust Centre page that carries the detail and the evidence.

ControlPositionDetail
Tenant isolationLogical isolation with per-tenant key scoping; dedicated and VPC options for physical isolation.Security
EncryptionIn transit and at rest. Customer-managed keys on Cloud Dedicated and all Enterprise models.Security
Secret handlingEncrypted secret references, injected at call time. Never in prompts, logs, manifests, exports or support tooling.Security
Access controlRBAC with segregation of duties, OIDC and SAML SSO, enforced MFA. SCIM not yet shipped.Security
Data residencySingapore default. Region chosen at workspace creation and immutable thereafter.Residency
Retention & deletionConfigured per tenant per data class. Deletion is verified and evidenced, including from backups on the stated cycle.Privacy
Audit immutabilityAppend-only records for the configured retention period. Export is itself an audited event.Governance
Model trainingNo customer data is used to train models, ours or a provider’s. Provider zero-retention terms are a condition of the approved model list.Responsible AI
Privileged accessBreak-glass only, four-eyes approved, time-bound, fully recorded, and surfaced to the tenant.Security
DLP & redactionConfigurable redaction on ingestion and on export, by data class, applied before model dispatch.Security
Incident responseDefined severities, notification commitments in the DPA, post-incident reports published to affected tenants.Status
SubprocessorsPublished live table with entity, purpose, data categories and region. Change notification by subscription.Subprocessors

What an audit actually gets.

Not a log file. A reconstructable account of a decision, scoped to the matter you asked about.

$ krewos audit export --matter SG-2291 --format json

run          r-8f21-4c  ·  2026-02-11T09:14:02+08:00  ·  2h 41m
release      4.2.0  ·  sha256:c41b9e7a…  ·  sealed 2026-02-03
components   41 pinned versions, each with checksum
model calls  17  ·  profile balanced-v3  ·  0 fallbacks fired
              provider jurisdictions: SG, SG, SG  (policy-constrained)
retrievals   41 chunks from 4 knowledge packs, each with
              source id, authority grade, date, relevance score
evidence     9 claims  ·  8 above floor  ·  1 abstained
policies     15 evaluated  ·  14 pass  ·  1 marginal (recorded)
actions      0 external effects  ·  no idempotency keys required
humans       1 approver, named · 2 edits with reasons
              · decision at 11:47  ·  elapsed in queue 2h 33m
autonomy     stage: regulated floor  ·  sampling: n/a (100%)
cost         412 platform + 289 model credits = S$7.01
              0 unattributed

export recorded as audit event a-9930 by user u-114
SCP

Scoped, not wholesale

Export by matter, by date range or by crew. An auditor asking about one matter does not receive every other client’s data, and the scope is recorded.

FMT

Machine-readable and signed

JSON and CSV for analysis, signed PDF for a bundle. The signature covers the record set, so tampering after export is detectable.

How the platform behaves when it does not know.

Most AI vendor assessments have no question for this, because no vendor has previously offered an answer. It is the section worth reading twice.

ABS

Abstention

Below the declared evidence floor the crew returns a structured insufficiency result naming what could not be established and which sources would resolve it. It routes to a human knowledge-gap queue and is reported separately from failures.

Conflict surfacing

Where sources of comparable authority disagree, both positions are carried forward with their authority and dates. No silent selection, and the conflict is visible on the artefact and in the export.

EXP

Staleness propagation

When a source expires or materially changes, every artefact that relied on it is identified and its owners are notified. You find out from the platform, not from a client.

What this does not do: it does not make the model correct. An evidence floor governs whether there is enough support to proceed, not whether the reasoning over that support is sound. Evaluation gates and human approval carry that load, which is why regulated output classes stay at 100% review permanently.

The document pack.

Click-through NDA, then immediate download. No sales call in between, and no form that routes to a queue.

DPA
Data Processing Agreement
Roles, processing purposes, subprocessor terms, transfer mechanism, breach notification commitments, deletion obligations.
NDA gated
SLA
Service Level Agreement
99.9% monthly Control Plane availability, exclusions, credit schedule, support response targets by severity.
NDA gated
PEN
Penetration test summary
Third-party annual test plus release-triggered testing. Summary letter with scope, methodology and remediation status.
NDA gated
WPR
Security whitepaper
Architecture, isolation model, secure SDLC, dependency and sandbox controls, privileged access, backup and disaster recovery.
NDA gated
CAI
Pre-answered CAIQ and SIG-lite
Completed, dated and maintained. Send us yours if it differs materially and we will complete it.
NDA gated
BCP
BCP / DR summary
RPO 15 minutes, RTO 4 hours on the standard tier, with the test cadence and the last test date.
NDA gated
INS
Insurance certificate
Professional indemnity and cyber cover, current certificate.
NDA gated
SUB
Subprocessor list
Entity, purpose, data categories and region. Published openly with change notification by subscription.
Open

Certification status, stated honestly

We publish where each certification actually stands rather than implying more. If a control is not yet independently assured, the Trust Centre says so on the page for that control.

Certifications & assurance →

Book a compliance review

60 minutes with a solutions engineer and, where useful, our security lead. Bring your questionnaire. We will complete it live rather than promise it by Friday.

Book a compliance review
KrewOS Packs

The domain expertise ships with the platform.

A KrewOS Pack is a licensed vertical package — Crew Templates, Knowledge Packs, deterministic policies, evaluation datasets and dashboards, maintained and dated by the publisher. You are not starting with an empty canvas and a jurisdiction problem.

Packs are licensed annually and separately from the platform subscription. Fees shown are indicative for the Singapore market.

A Pack is not a prompt library.

Six things ship inside every Pack, and every one of them is versioned, dependency-locked and covered by an evaluation suite before the Pack is published to entitled tenants.

CT

Crew Templates

Complete, runnable crew designs with typed ports, declared effects and approval gates already positioned where the risk actually sits.

KP

Knowledge Packs

Curated, source-attributed corpora with authority tiers, freshness windows and access-control rules. Each source carries a dated currency assertion.

PP

Policy Packs

Deterministic rules that run outside the model — jurisdiction routing, mandatory clause checks, threshold tests, escalation triggers.

EV

Evaluation datasets

Graded cases drawn from real disputed work, with pass thresholds that gate promotion. A Pack update that regresses the suite is not published.

DB

Dashboards & outcome units

The unit of business outcome is declared by the Pack — a matter reviewed, a reconciliation closed — so cost per outcome is reported from day one.

CU

Currency assertions

Every Pack states what it tracks, how often, and the date it was last asserted current. When a source changes, dependent artefacts and their owners are identified.

Maintained Packs

A Maintained Pack is a subscription, not a download. The publisher keeps the knowledge, the policies and the evaluation suite current, and entitled tenants receive dated change notifications. Compatible updates may be recommended; they are never installed silently.

Launch catalogue

4 Packsas of 14 Aug 2026
PackVersionVerificationCrew TemplatesAgentsCurrency assertedTracking cadenceLicence / yr
Singapore Legal Practice Packv6.3.0wGrow verified41912 Aug 2026Statutes weekly · release quarterlyS$18,000
MAS Financial Compliance Packv4.1.2wGrow verified31614 Aug 2026Circulars daily · release quarterlyS$24,000
Aquaculture Operations Packv2.0.0wGrow verified31231 Jul 2026Advisories monthly · release half-yearlyS$9,000
SG Tender Response Packv1.4.0Tested2905 Aug 2026Tender notices daily · release quarterlyS$9,000

Singapore Legal Practice

v6.3.0

Jurisdiction routing, Singapore clause libraries, privilege and confidentiality handling, and LawCrew document-review templates with permanent full human review on regulated output.

LegalSingaporeEN · ZHrisk: high

Statutes and reported judgments tracked weekly. Currency asserted 12 Aug 2026.

View the Pack

MAS Financial Compliance

v4.1.2

Controls mapping, reconciliation and exception policies, dual-approval templates and outcome dashboards for entities regulated by the Monetary Authority of Singapore.

Financial servicesSingaporeENrisk: high

Circulars and notices tracked daily. Currency asserted 14 Aug 2026.

View the Pack

Aquaculture Operations

v2.0.0

Species and regional knowledge, water-chemistry safety rules, telemetry connectors and specialist escalation routing for farm groups across Singapore, Malaysia and Indonesia.

AquacultureSG · MY · IDEN · IDrisk: medium

Regional advisories tracked monthly. Currency asserted 31 Jul 2026.

View the Pack

Filter the catalogue

Packs and their components are classified across fourteen dimensions. The same filters drive template recommendation inside Studio.

IndustryJurisdictionLanguageRisk levelHuman control levelInput typeOutput typeConnector dependencyVerification statusMaintained
Pack licences are annual and are held by the organisation, not by a seat. A licensed Pack is entitled across every workspace in your tenant unless you scope it deliberately.
Pack trials are not available on the free trial plan. A Pack trial is a scoped 30-day entitlement arranged with a solutions engineer, because the evaluation datasets and policy rules are the licensed asset.
Maintained Pack · Published by wGrow Technologies

MAS Financial Compliance Pack

Controls mapping, reconciliation and exception policies, dual-approval templates and outcome dashboards for entities regulated by the Monetary Authority of Singapore. Circulars and notices are tracked daily; the Pack states the date it was last asserted current.

KrewOS is not certified, approved or endorsed by MAS. Regulatory obligations remain those of the licensed entity.

Version
v4.1.2
Crew Templates
3
Agents
16
Currency asserted
14 Aug 2026
Verification
wGrow verified
Licence
S$24,000 / yr

What is inside

The most expensive Pack in the catalogue, because the tracking cadence is daily and the deterministic policy surface is the largest. Nothing in it does model arithmetic on a figure that has to reconcile.

Component classCountExamplesHuman control
Crew Templates3Finance Close · Regulatory Reporting Assembly · Third-Party Risk AssessmentDual approval
Pods6Reconciliation · Exception Handling · Controls Testing · Evidence AssemblyInherited
Agents16Ledger Matcher · Variance Explainer · Circular Change Classifier · Outsourcing Risk ScorerInherited
Knowledge Packs5MAS notices and circulars · guidelines library · FRS accounting standards · internal policy shell · prior-period workpapersRead-only
Policy Packs18Materiality thresholds · dual-approval triggers · deterministic calculation verification · segregation-of-duties checksDeterministic
Evaluation suites6512 graded cases including seeded misstatements and deliberately incomplete evidenceRelease gate
Dashboards4Reconciliations closed · exceptions by ageing · control test results · cost per closeReporting

Controls the CFO asks about

These are enforced by the runtime and the compiler, not by instructions in a prompt.

2AP

Dual approval

Configured high-risk actions require two distinct named approvers with segregation-of-duties checked against your directory. The second approver cannot be the preparer.

CALC

Deterministic calculation

Every figure that has to reconcile is computed by a deterministic node. The model explains variances; it does not do the arithmetic.

IDEM

No duplicate effects

Postings, filings and notifications carry idempotency keys and declared compensation behaviour. The same journal is not posted twice.

BUD

Budgets that bind

Soft limits degrade model tier or concurrency; hard limits fail closed before spending. Per run, per project, per tenant.

ATTR

Full cost attribution

Every credit is attributed to a run, a node, a model profile and an outcome unit. There is no unattributed spend to explain to an auditor.

TRC

Exportable trace

Run to node to model call to retrieval to approval, in machine-readable form, with immutable Correction Records for every human decision.

Tracked sources and asserted currency

Daily tracking is the reason this Pack exists. A circular published on Monday is classified and impact-assessed against your live crews by Tuesday, and the change notice names the components affected.

SourceAuthority tierRefreshCurrency assertedDocuments
MAS noticesPrimaryDaily14 Aug 2026418
MAS circulars and information papersPrimaryDaily14 Aug 20261,106
MAS guidelines (including TRM and outsourcing)PrimaryWeekly11 Aug 202692
Singapore Financial Reporting StandardsSecondaryQuarterly30 Jun 2026147
Internal policy shell and prior workpapersTenant-ownedOn changeYour entity

Evaluation coverage

Gate passing
SuiteCasesThresholdLast run
Reconciliation exception detection14899%99.3%
Seeded misstatement recall96100%100%
Circular impact classification10496%97.1%
Abstention on incomplete evidence7497%98.6%
Dual-approval routing correctness52100%100%
Deterministic calculation parity38100%100%

Licence terms

Licence fee
S$24,000 / year
Term
Annual, auto-renewing
Scope
Tenant-wide, all workspaces
Maintenance
Included — quarterly releases
Source tracking
Daily, with change notices
Change notice
14 days before a breaking release
Deployment
Cloud, Dedicated, Customer VPC, Hybrid, Private
Governance evidence pack
Quarterly, included
Entitled tenants receive a quarterly governance evidence pack — control test results, evaluation trends, abstention rates and review-rate trajectory — in a form a board paper can cite.
This Pack maps its controls to named MAS guidance. That mapping is wGrow's assessment, published so you can audit it — it is not a MAS determination, and MAS does not certify, approve or endorse vendor software. Your entity remains responsible for its regulatory obligations, including any outsourcing and third-party risk assessment of KrewOS itself.

Request the controls mapping

The full mapping from Pack policies to named MAS guidance, released under the click-through NDA alongside the DPA and the penetration-test summary.

Open the document portal

Book a compliance review

Ninety minutes with a solutions engineer and your MLRO or head of compliance, working from your own control framework.

Book a review
Maintained Pack · Published by wGrow Technologies

Aquaculture Operations Pack

Species and regional knowledge, water-chemistry safety rules, telemetry connectors and specialist escalation routing. Built so that a confident wrong answer about water chemistry at 5am is not a thing the system is capable of producing.

AquaMind supports a technical decision-maker. It does not replace a veterinarian or a licensed technical specialist.

Version
v2.0.0
Crew Templates
3
Agents
12
Currency asserted
31 Jul 2026
Verification
wGrow verified
Licence
S$9,000 / yr

What is inside

Version 2.0.0 is a breaking release: the safety-gate policy surface was rewritten to make every recommendation carry a required-reading list, and telemetry connectors moved to the governed Action contract.

Component classCountExamplesHuman control
Crew Templates3AquaMind Advisory · Water Quality Incident Response · Feed Programme ReviewSafety gate
Pods5Dynamic Routing · Expert Advisory Panel · Evidence Verification · Telemetry CheckInherited
Agents12Species Router · Water Chemistry Specialist · Disease Pattern Analyst · Escalation ClassifierInherited
Knowledge Packs7Species profiles · regional disease advisories · water-chemistry references · feed conversion literature · regulatory notices SG/MY/IDRead-only
Policy Packs14Dissolved-oxygen thresholds · salinity and temperature bounds · treatment withdrawal periods · mandatory escalation triggersDeterministic
Evaluation suites4286 cases built from real farm incidents, including 61 where the correct answer is an abstentionRelease gate
Connectors6Pond sensor gateways, feed system exports, laboratory result importsGoverned Actions

Why abstention matters most here

Twenty-one per cent of the evaluation suite consists of cases where the only correct behaviour is to decline. That is deliberate, and it is measured on every release.

FLR

Evidence floor

Below the declared floor the crew states what it could not establish and which reading, sample or laboratory result would resolve it. It does not produce a best guess.

SAFE

Safety gates

Deterministic bounds on dissolved oxygen, salinity, temperature, stocking density and treatment withdrawal run outside the model and cannot be argued with.

ESC

Specialist escalation

Contested advice, suspected notifiable disease and any recommendation touching treatment chemicals route to a named technical specialist before it reaches the farm.

TEL

Telemetry cross-check

Advice is checked against the pond's own recent readings. Where the panel's view and the telemetry disagree, both are carried forward and flagged.

OFF

Intermittent connectivity

Runs are durable. A case started on a boat and approved eight hours later on shore is a normal state, not a timeout.

LNG

Field languages

English and Bahasa Indonesia output, mobile-sized approval tasks, and a recommendation format a farm manager can act on without a laptop.

Coverage

BarramundiTilapiaGrouperShrimp — vannameiMilkfish
SingaporeMalaysiaIndonesiaEnglishBahasa Indonesiarisk: medium
Not covered: salmonid species, cold-water systems, and any jurisdiction outside SG, MY and ID. Regional advisories refresh monthly; the Pack releases half-yearly.

Licence terms

Licence fee
S$9,000 / year
Term
Annual, auto-renewing
Scope
Tenant-wide, unlimited farm sites
Maintenance
Included — half-yearly releases
Advisory tracking
Monthly
Connectors
Six included; bespoke gateways quoted
Change notice
30 days before a breaking release
Fork rights
Yes, lineage retained
Book a demo with your telemetry
KrewOS Hub · Public view

A catalogue, not a marketplace.

Verified Agents, Pods, Crew Templates and licensed Packs — classified across fourteen dimensions, versioned, dependency-locked and tested. Browse the whole catalogue without an account. Use it with one.

Every component here has been reviewed. There is no unrestricted publishing, and there never will be.

Agents
312
Pods
86
Crew Templates
24
Packs
4
wGrow verified
241
Catalogue updated
14 Aug 2026
Industry: LegalJurisdiction: SingaporeLanguage: EnglishRisk: anyHuman control: anyConnector: none312 → 47 results
ComponentVersionClassificationDeclared effectsHuman controlVerificationEval pass
SG Statute Retrieval Agentv3.1.0Legal · SG · EN · risk highReads onlyInheritedwGrow verified99.2%
Jurisdiction Routerv2.9.4Legal · SG · MY · ENReads onlyInheritedwGrow verified99.0%
Adversarial Clause Reviewerv2.4.1Legal · SG · EN · risk highReads onlyApproval requiredwGrow verified97.7%
Privilege Screenv1.9.4Legal · SG · EN · deterministicReads onlyDeterministicwGrow verified100%
Matter Intake Classifierv1.4.0Legal · SG · EN · risk mediumReads onlyInheritedTested94.1%
Ledger Matcherv4.2.0Financial services · SG · ENReads onlyDeterministicwGrow verified100%
CRM Opportunity Writerv3.0.2Cross-industry · EN · connectorExternal ActionApproval requiredwGrow verified98.4%
Water Chemistry Specialistv2.0.0Aquaculture · SG MY ID · EN IDReads onlySafety gatewGrow verified98.6%
Bilingual Editorial Reviewerv2.7.1Content · EN · ZH · risk lowReads onlyInheritedTenant verified96.2%
Legacy Summariserv1.0.4Cross-industry · ENReads onlyInheritedDeprecated

What is public, and what needs an account

This split is a product decision, not an oversight. Listings, classification and evaluation summaries are public because a technical evaluator should be able to judge the catalogue before speaking to anyone. Manifests, evaluation datasets and verified cost figures are the licensed asset and the attack surface, so they are not.

DetailPublic, no accountRequires an accountWhy
Listing, purpose, owner, version historyPublicDiscoverability is the point of a catalogue
Classification across all fourteen dimensionsPublicLets an evaluator judge fit without a sales call
Typed input and output summaryPublicInterface shape is not a secret
Declared effects and human-control levelPublicA buyer must be able to see what a component can cause
Evaluation summary — suite names, thresholds, pass ratePublicThe claim is checkable; the data behind it is licensed
Full Crew Manifest and component definitionsSigned inPrompts, policies and routing logic are the licensed IP
Evaluation datasets and graded casesSigned in · entitledBuilt from real disputed work; publishing them destroys the suite
Verified cost per outcome and credit figuresSigned inFigures without your volumes and posture mislead
Use, Configure or ForkSigned inLineage requires an identity to attach it to

Verification tiers

What each tier actually required, rather than what it sounds like.

DR

Draft

Authored and validated against the manifest schema. Not evaluated. Visible only inside the authoring tenant.

TS

Tested

Passes its own declared evaluation suite at the stated threshold, with a reproducible run recorded against a pinned release.

WV

wGrow verified

Reviewed by a named wGrow engineer and a domain reviewer: effect declaration audited, prompt-injection paths checked, evaluation suite judged adequate for the stated risk level.

TV

Tenant verified

Verified by your own organisation against your own bar, in your private catalogue. Yours to publish internally without publishing to the world.

DP

Deprecated

Superseded or withdrawn. Existing releases keep running; new installs are blocked and owners are notified with the replacement.

PR

Private catalogues

Components you build stay yours by default. Publishing to the public Hub is an explicit act with a review step, never a default.

Agent · KrewOS Hub · Singapore Legal Practice Pack

SG Statute Retrieval Agent

Retrieves Singapore statutory provisions and subsidiary legislation relevant to a stated legal question, returns each provision with its authority tier, in-force date and amendment history, and scores the sufficiency of the retrieved set against the claim it is being asked to support.

Public view. The full manifest, the evaluation dataset and verified cost figures require an account.

Version
v3.1.0
Verification
wGrow verified
Declared effects
Reads only
Risk level
High
Evaluation pass
99.2%
Published
28 Jul 2026

Typed interface

Public
PortDirectionTypeRequiredNotes
questioninLegalQuestionYesFree text plus a declared practice area
governing_lawinJurisdictionYesRefuses to connect to a router that cannot emit this
as_atinDateNoDefaults to run start; supports point-in-time retrieval
provisionsoutEvidenceSetEach item carries authority tier, in-force date, amendment chain
sufficiencyoutSufficiencyScoreScored against the claim, compared to the crew's evidence floor
gapsoutKnowledgeGap[]Named missing sources when the floor is not met

Classification

Industry
Legal
Jurisdiction
Singapore
Language
English
Risk level
High
Human control
Inherited from crew
Input type
Structured question
Output type
Evidence set
Connector dependency
None
Knowledge dependency
3 Knowledge Packs
Quality status
wGrow verified

Declared effects

No external side effects
RD
Reads
SG statutes, subsidiary legislation and practice directions Knowledge Packs. Nothing else.
WR
Writes
Evidence records and retrieval traces into the run's own audit store.
SP
Spends
Platform credits for retrieval and reranking; model credits for query expansion only.
EX
Causes externally
Nothing. The compiler proves no path from this component reaches an external Action.

Evaluation summary

Gate passing
SuiteThresholdResultTrend
Citation accuracy99%99.2%
In-force date correctness100%100%
Sufficiency calibration95%96.4%
Abstention when floor unmet97%98.1%

Behind the signup gate

Three things on this page are deliberately not public. This is the same decision explained on the Hub browse page — the interface is public so you can judge fit, the implementation is licensed so it stays an asset.

Crew Manifest

Signed in
component: sg-statute-retrieval
version: 3.1.0
ports:
  — shown above, public —
knowledge:
  [ 3 packs — signed in ]
prompts:
  [ 4 templates — signed in ]
policies:
  [ 6 rules — signed in ]

The public JSON Schema for the manifest format itself is open and documented.

Sign in to view

Evaluation dataset

Entitled tenants

124 graded cases, each with the disputed question, the expected provision set, the expected sufficiency band and the correction that produced it. Built from real reviews at Singapore practices.

Publishing a graded evaluation set destroys it. Once the answers are public, the suite stops measuring anything.
Request entitlement

Verified cost figures

Signed in

Median platform and model credits per invocation, cost per outcome unit, and the distribution across corpus sizes — measured on real runs, not estimated.

A single number without your volumes, document sizes and review posture misleads more than it informs, which is why the estimator asks for those first.

Open the estimator

Version history

VersionReleasedChangeBreakingVerification
v3.1.028 Jul 2026Point-in-time retrieval via as_at; amendment chain added to every provisionNowGrow verified
v3.0.219 May 2026Sufficiency calibration retuned after 41 Correction Records from three tenantsNowGrow verified
v3.0.002 Mar 2026provisions output changed from a flat list to a typed EvidenceSetYeswGrow verified
v2.3.114 Nov 2025Subsidiary legislation corpus addedNowGrow verified
Trust Centre

Your compliance team will ask. The answers are already here.

Security, privacy, residency and assurance for KrewOS, published in full and kept current. Most vendors make you send a questionnaire and wait three weeks. We would rather you read it now and tell us what is missing.

Security contact: security@krewos.ai · Disclosure policy published at /.well-known/security.txt · Last reviewed 14 Aug 2026

Control Plane
Operational
Execution Plane · SG
Operational
Model Gateway
Degraded
KrewOS Hub
Operational
90-day uptime
99.97%
Full history

Everything in one place

Twelve pages, no gate except where a document genuinely needs one. If a control you need is not documented here, it is a gap in our writing, not a trick — email the security contact and we will publish it.

SEC

Security

Tenant isolation, encryption, secret handling, identity, secure SDLC, sandboxing, privileged access, DLP and redaction, backup and disaster recovery. Written to answer your questionnaire before it is sent.

RES

Data residency & sovereignty

Singapore-only at launch, the Control Plane and Execution Plane split explained for a non-architect, and the five deployment tiers with what each one moves.

PDP

Privacy & PDPA

Controller and processor roles, obligation-by-obligation mapping, retention and deletion, data-subject handling, cross-border transfer and the DPA.

MAS

Sector alignment — MAS & professional

Mapping to named MAS guidance, outsourcing and third-party risk, FEAT principles, professional-conduct considerations, and an explicit non-certification statement.

SUB

Subprocessors

Every entity, what it processes, which data categories it touches and where it sits. Change notifications 30 days in advance, with an objection window.

CRT

Certifications & assurance

ISO/IEC 27001 and SOC 2 Type II are in progress with target dates. We say so plainly rather than implying otherwise.

DOC

Document portal

Self-serve access to the DPA, SLA, penetration-test summary, architecture overview and pre-answered questionnaire behind a click-through NDA. Minutes, not weeks.

RAI

Responsible AI & model policy

Abstention below the evidence floor, named human accountability, no autonomous high-impact actions, bounded loops, evaluation gates, and the approved model list.

UPT

Status & uptime

Component and region status, uptime history, incident post-mortems and maintenance calendar — hosted separately from the platform it reports on.

LEG

Legal hub

Master agreement, DPA, SLA, acceptable use, privacy and cookie policies, Pack licence terms and the subprocessor addendum, all versioned with effective dates.

GOV

How governance is enforced

The product mechanics behind these claims: evidence and abstention, progressive autonomy, compile-time effect proofs, Correction Records and audit export.

DEP

Deployment options

Cloud, Cloud Dedicated, Customer VPC, Hybrid and Private. Central governance in every shape, with execution wherever your obligations require it.

At a glance

The facts a risk gatekeeper checks first. Each links to the page that substantiates it.

QuestionAnswerDetail
Primary data regionSingapore. Chosen at workspace creation and immutable thereafter.Residency
Deployment optionsCloud · Cloud Dedicated · Customer VPC · Hybrid · Private/LocalDeployment
EncryptionTLS 1.3 in transit, AES-256 at rest. Customer-managed keys on Regulated tier.Security
IdentityOIDC and SAML SSO, MFA, RBAC, SCIM provisioning on Professional and above.Security
Model training on your dataNever. No customer content is used to train any model, ours or a provider's. Zero-retention endpoints are a condition of the approved model list.Responsible AI
Availability commitment99.9% monthly on the shared Control Plane, excluding published maintenance and third-party provider outages. A contract term rather than a plan feature — it binds us where your contract carries it, and we do not claim it where it does not.Status
If we miss itA service credit against your next invoice — 10%, 25% or 50% of that month's base — computed from the published attainment and issued without a claim. Three months below 99.0% in a rolling twelve ends the contract without penalty.Schedule
Recovery targetsRPO ≤ 15 minutes, RTO ≤ 4 hours on the standard tier. Published as targets, not commitments — unlike availability they carry no service credit, and we would rather say so than blur the two.Security
Audit recordsImmutable, append-only, exportable in machine-readable form. Corrections supersede; they never rewrite.Governance
Penetration testingAnnual third-party, plus a release-triggered test on any change to the effect compiler or the secrets gateway. Summary letter available under NDA.Certifications
Certification statusISO/IEC 27001 in progress, Stage 1 audit booked. SOC 2 Type II observation window open. Neither is achieved yet, and we do not imply that it is.Certifications
SubprocessorsNine, all listed with data categories and regions. 30 days' notice before any addition.Subprocessors
Incident notificationWithin 24 hours of confirmation for any incident affecting your data, with a written post-mortem inside 10 business days.Security

“We publish the unflattering parts on purpose. A vendor that claims ISO 27001 before the certificate exists is telling you exactly how it will handle the next inconvenient fact. Our certification page states what is not finished and when it will be — and we would rather lose a deal on that page than win one and be found out during an audit.”

Head of Security & Compliance, wGrow Technologies Pte Ltd

Get the documents

Click-through NDA

DPA, SLA, penetration-test summary, architecture overview, pre-answered CAIQ and SIG-lite, business continuity summary and the insurance certificate. Accept the NDA in the browser and download immediately — no sales call in between.

DPASLAPentest summaryArchitecture overviewCAIQSIG-liteBCP/DRInsurance
Open the document portal

Report something

48h triage

Coordinated disclosure, no legal threats, credit where you want it. We acknowledge within one business day, triage within 48 hours and agree a disclosure timeline with you.

Security contact
security@krewos.ai
Privacy / DPO
dpo@krewos.ai
Disclosure policy
/.well-known/security.txt
Acknowledgement
1 business day
Triage
48 hours
Safe harbour
Yes, for good-faith research
Vulnerability disclosure policy
Trust Centre · Security

Written to answer the questionnaire before you send it.

Every control below is described the way an assessor would want it described: what it is, how it is enforced, and what it does not cover. Where a control is only on certain tiers, the tier is named. Where something is planned rather than shipped, it says planned.

Pre-answered CAIQ and SIG-lite are available under the click-through NDA. Last reviewed 14 Aug 2026.

Architecture and tenant isolation

KrewOS separates a Control Plane — identity, catalogue, manifests, policies, evaluations, releases — from an Execution Plane that runs compiled plans and holds run state. Every request carries a tenant context that is resolved at the edge and enforced at the data layer, not in application code that a bug could bypass.

TEN

Tenant isolation

Row-level isolation on every table with tenant scoping enforced by the database, plus separate object-storage prefixes with per-tenant encryption context. Cross-tenant queries are structurally impossible, not merely disallowed.

NET

Network segmentation

Private subnets for all data stores, no public database endpoints, egress restricted to an allow-listed model gateway and declared connectors. Administrative access only through an authenticated bastion with session recording.

SBX

Execution sandboxing

Generated and custom code runs in ephemeral, resource-capped sandboxes with no ambient credentials, a restricted filesystem and network access limited to declared endpoints. Sandboxes are destroyed after each run.

GWY

Secrets gateway

Credentials are injected at the point of call by a gateway process. Keys never appear in prompts, logs, manifests, exports, support tooling or crash dumps, and are never returned by any API.

CMP

Compile-time effect proof

Before a release exists, the compiler statically proves that no path runs from untrusted input to an external side effect without an intervening approval gate. If the property fails, there is no release to deploy.

DED

Dedicated options

Cloud Dedicated gives you isolated execution resources; Customer VPC and Private deployment move the Execution Plane into infrastructure you control, with the Control Plane still governing centrally.

Control summary

The scannable version. Availability by tier is stated where it differs.

DomainControlHow it is enforcedAvailabilityState
EncryptionIn transitTLS 1.3, HSTS, modern cipher suites only; internal service-to-service traffic mutually authenticatedAll tiersShipped
EncryptionAt restAES-256 on all volumes, object storage and backups, with per-tenant encryption contextAll tiersShipped
EncryptionCustomer-managed keysYour KMS key, revocable; revocation renders tenant data unreadable within the rotation windowRegulated tierShipped
IdentitySSO — OIDC and SAMLDomain-based discovery at sign-in; just-in-time provisioning with group-to-role mappingProfessional and aboveShipped
IdentityMFATOTP and WebAuthn; enforceable tenant-wide, mandatory for administrator rolesAll tiersShipped
IdentitySCIM provisioningUser and group lifecycle synchronised from your directory; deprovisioning revokes sessions immediatelyProfessional and aboveShipped
AccessRBAC and segregation of dutiesRole sets aligned to the platform personas; approver cannot be preparer where dual approval is configuredAll tiersShipped
AccessPrivileged accessNo standing production access. Time-boxed, four-eyes-approved, ticket-linked, fully session-recorded and surfaced in your tenant audit logAll tiersShipped
AccessSupport impersonationRequires explicit tenant consent per session, is read-only by default, is time-limited and appears in your audit trail while it is happeningAll tiersShipped
SDLCCode review and branch protectionTwo-reviewer requirement on the compiler, the secrets gateway and the policy engine; signed commits; no direct pushes to release branchesn/aShipped
SDLCDependency and secret scanningSCA and secret detection on every pull request and nightly on all release branches; critical findings block the buildn/aShipped
SDLCSAST and container scanningStatic analysis on every build; base images rebuilt and rescanned weekly with a 7-day critical patch targetn/aShipped
DataDLP and redactionConfigurable detection and redaction of identifiers before content reaches a model provider, with the redaction map retained inside your regionProfessional and aboveShipped
DataPrompt and output logging controlsPer-project setting for whether prompt and completion bodies are retained; metadata and evidence references are always retainedAll tiersShipped
ResilienceBackup and restoreContinuous write-ahead archiving with point-in-time recovery; restores rehearsed quarterly and the result recordedAll tiersShipped
ResilienceRecovery targetsRPO ≤ 15 minutes, RTO ≤ 4 hours standard; tighter targets available by agreement on the Regulated tierAll tiersShipped
MonitoringSecurity loggingCentralised, tamper-evident logs with 400-day retention; authentication, authorisation, privileged access and effect execution are all loggedAll tiersShipped
MonitoringAnomaly detection on agent behaviourAlerting on abnormal effect frequency, budget burn and retrieval patterns per crewProfessional and abovePlanned Q4 2026
AssuranceBug bountyPrivate programme with invited researchers; public programme deferred until the disclosure process has run a full yearn/aPrivate only

Incident response

24h notification
1
Detect and declare
Automated alerting plus a 24×7 on-call rota. Any suspected incident is declared within 30 minutes of triage rather than after confirmation.
2
Contain
Credential rotation, session revocation and tenant-level isolation are pre-scripted and rehearsed, not improvised during the event.
3
Notify
Affected tenants notified within 24 hours of confirmation, with what is known, what is not yet known and what you should do. PDPC notification handled in line with the PDPA where thresholds are met.
4
Post-mortem
Written, blameless, shared with affected tenants within 10 business days and summarised publicly on the status page.

People and process

Background screening
All staff, pre-employment
Security training
Onboarding plus annual
Secure-coding training
Engineers, annual
Phishing simulation
Quarterly
Access review
Quarterly, evidenced
Device management
MDM, disk encryption, EDR
Offboarding
Access revoked same day
Vendor review
Annual, risk-tiered
Policy set
17 documents, annually reviewed
The full policy index, including which policies are available for review under NDA, ships in the security pack.

Threats specific to agent platforms

Generic SaaS controls do not cover the interesting risks here. These four are where an agent platform actually gets hurt, and each has a structural answer rather than a policy answer.

RiskWhy it is differentStructural control
Prompt injection reaching an external actionInstructions hidden in a retrieved document can attempt to steer an agent into sending, posting or payingThe compiler proves at build time that no untrusted-input path reaches a declared external effect without an approval gate. This is a proof, not a filter, and it is outside the model where injection cannot reach it.
Credential exfiltration through model outputA model that can see a secret can be persuaded to repeat itModels never see credentials. The secrets gateway injects them at the call boundary; the model receives an opaque reference.
Runaway loops and cost exhaustionAutonomous retry logic can spend a month's budget in an hourLoops are bounded at design time and rejected by the editor if unbounded. Soft budget limits degrade model tier or concurrency; hard limits fail closed before spending.
Silent quality regressionA prompt or model change degrades output with no error and no alertImmutable releases with locked dependencies and evaluation gates that block promotion, plus automatic reversion of autonomy when measured accuracy breaches its bound.
Two honest limits. First, a Customer VPC or Private deployment moves execution into your infrastructure, which means the controls on your side of that boundary become yours to operate — we document the split precisely rather than implying we still cover it. Second, model providers are subprocessors with their own security posture; ours is described here, theirs is named on the subprocessor page.

Get the evidence

Penetration-test summary letter, architecture overview, pre-answered CAIQ and SIG-lite, BCP and DR summary and the insurance certificate, all under a click-through NDA.

Open the document portal

Talk to the people who built it

A technical review with the engineers who wrote the effect compiler and the secrets gateway. Bring your architects and your questionnaire.

Book a technical review
Trust Centre · Data residency & sovereignty

Singapore only, and we will show you exactly where the line is.

Every workspace is created in the Singapore region. Customer content, run state, evidence and audit records stay there. The region is chosen at workspace creation and cannot be changed afterwards — that is a deliberate constraint, and it is stated on the creation screen in bold.

Singapore is the only region at launch. No additional regions are committed; if one is added, existing workspaces are unaffected.

Primary region
Singapore
Regions available
1
Region mutability
Immutable
Chosen at
Workspace creation
Backups
In-region only
Support tooling
In-region only

The plane split, without the architecture diagram

KrewOS separates governance from execution. The Control Plane decides what is allowed; the Execution Plane does the work and holds the data. Keeping those apart is what lets one governance model coexist with strict residency, because the two do not have to live in the same place.

Control Plane

Governance

Holds identity, the component catalogue, Crew Manifests, policies, evaluation suites, releases and entitlements. It knows what your crews are allowed to do. It does not hold the documents they work on.

Identity & RBACCatalogueManifestsPoliciesEvaluationsReleasesEntitlementsBilling metadata

Execution Plane

Your data

Runs the compiled plan and holds run state, retrieved content, generated artefacts, evidence records, human decisions and the audit trail. This is where your data actually is, and it is the plane that moves under the enterprise deployment tiers.

Run stateKnowledge contentRetrieved evidenceGenerated artefactsCorrection RecordsAudit trailSecrets references

Five deployment tiers

Governance stays central in all five. What changes is where execution runs and who operates the infrastructure underneath it.

TierWhere execution runsWhere your content sitsOperated byTypical buyerCMK
KrewOS CloudManaged, shared, SingaporeKrewOS Singapore regionwGrowSME and standard enterpriseNo
KrewOS Cloud DedicatedManaged, dedicated resources, SingaporeKrewOS Singapore region, isolatedwGrowHigher isolation or performance needsYes
Enterprise — Customer VPCYour cloud accountYour account, your regionShared — we deploy, you own the accountResidency rules and private-system accessYes
Enterprise — HybridLocal runtime, central governanceYour premises for knowledge and run stateSharedPrivate data with managed governanceYes
Enterprise — Private / LocalYour infrastructureEntirely yoursYou, with our supportRestricted or disconnected environmentsYes

What never leaves the region

On KrewOS Cloud, the following data classes are stored and processed only in Singapore. Where something does cross a boundary, it is named here rather than omitted.

Data classStored inProcessed inLeaves the region?
Knowledge Pack content and embeddingsSingaporeSingaporeNever
Run state, checkpoints and artefactsSingaporeSingaporeNever
Evidence records and retrieval tracesSingaporeSingaporeNever
Human decisions and Correction RecordsSingaporeSingaporeNever
Audit trail and exportsSingaporeSingaporeNever
Backups and point-in-time archivesSingaporeSingaporeNever
Support and diagnostic toolingSingaporeSingaporeNever
Model inference payloadsNot stored by the providerSingapore-resident endpointsOnly to approved in-region endpoints
Account and billing metadataSingaporeSingaporeNever
Aggregate platform telemetry (no content)SingaporeSingaporeNever

Model provider residency

A model profile declares the jurisdictions its endpoints may sit in and the retention terms required of the provider. The runtime refuses to route to an endpoint outside the declared set, so residency is enforced by configuration rather than by an operator remembering.

1
In-region endpoints only
Approved models must offer a Singapore-resident endpoint to be added to the list.
2
Zero retention required
Providers must contractually agree to no retention and no training on submitted content.
3
Bring your own key
Use your own provider contracts and your own negotiated terms; we hold the credential as an encrypted reference and never in a prompt.
4
Private model adapters
Point the gateway at a model you host yourself, including inside a disconnected environment.

Region immutability

Cannot be changed

A workspace's region is fixed at creation. Changing it later would be a full data migration for both parties, so we do not offer it as a setting that looks reversible when it is not.

Chosen at
Workspace creation
Changeable later
No
Migration path
New workspace, exported manifests
What migrates
Manifests, components, policies
What does not
Run history, audit trail
Multiple regions per tenant
Supported once a second region exists
If your obligations require data to sit outside Singapore today, the answer is a Customer VPC or Private deployment, not a region setting we do not have.
Trust Centre · Privacy & PDPA

Designed to support your PDPA obligations.

Compliance with the Personal Data Protection Act is an obligation of the organisation that controls the data — which is you, not us. KrewOS is designed to make discharging it straightforward, and this page maps each obligation to the mechanism that supports it. We do not describe the product as "PDPA compliant", because no tool can be.

Data protection contact: dpo@krewos.ai · DPA version 2.3, effective 01 Jul 2026

Who is who

Getting the roles right determines who answers a data-subject request and who notifies the PDPC. It is the first question a competent DPO asks.

DataYou arewGrow isBasis
Content your crews process — documents, matters, recordsOrganisation with controlData intermediaryDPA, processing only on your documented instructions
Knowledge Pack content you uploadOrganisation with controlData intermediaryDPA
Evidence records and Correction RecordsOrganisation with controlData intermediaryDPA
Your users' account data — name, work email, roleOrganisation with controlOrganisation with control, jointly for platform administrationContract performance and legitimate interests
Support correspondence and billing recordsOrganisation with controlContract performance and legal obligation
Marketing-site enquiriesOrganisation with controlConsent

PDPA obligations, and what supports them

The nine obligations, each with the specific product mechanism you would point at during an assessment. The obligation remains yours in every row.

ObligationYour responsibilityWhat KrewOS provides
ConsentObtaining and recording consent from your individualsNo collection of personal data from your individuals by us; purpose-scoped Knowledge Packs so content is only retrievable by the crews you authorise
Purpose limitationDefining permitted purposesPer-project knowledge scoping and access-control lists, plus declared effects so a component cannot quietly use data for something else
NotificationTelling individuals what you doDocumented processing description in the DPA you can incorporate into your own notices
Access & correctionResponding within statutory timelinesSearch across knowledge, runs and evidence by identifier; export in machine-readable form; corrections recorded as append-only Correction Records that supersede without erasing the trail
AccuracyEnsuring data is accurateSource-attributed retrieval with authority tiers and dated currency, staleness propagation when a source changes, and abstention rather than invention below the evidence floor
ProtectionReasonable security arrangementsThe full control set on the security page — isolation, encryption, access control, logging, incident response
Retention limitationSetting retention periodsConfigurable retention per data class with automatic deletion, plus legal hold on the Regulated tier
Transfer limitationAssessing cross-border transfersSingapore-only storage and processing; model endpoints constrained to approved in-region jurisdictions by the model profile; subprocessor list published with regions
Data breach notificationAssessing and notifying the PDPC and individualsNotification to you within 24 hours of confirmation, with the facts needed for your assessment, and a written post-mortem within 10 business days

Retention and deletion

Data classDefaultConfigurableOn termination
Knowledge contentUntil deletedYes30 days, then deleted
Run state and artefacts12 monthsYes30 days, then deleted
Evidence records12 monthsYes30 days, then deleted
Audit trail7 yearsYesExportable, then deleted per your instruction
Prompt and completion bodies30 daysYes, or offDeleted with the workspace
Backups35 days rollingNoExpire on the rolling window
Account and billing records7 yearsNoRetained — statutory requirement

Handling a data-subject request

Self-serve
1 · Locate
2 · Export
3 · Correct or delete
4 · Evidence
LO
Locate
Search knowledge, run history, evidence records and human decisions by identifier across the workspace. You do not need to raise a ticket with us.
EX
Export
Machine-readable export of everything found, with provenance, so the response you send is defensible.
CO
Correct or delete
Corrections are recorded as append-only records that supersede prior values; deletions remove content and its derived embeddings, and are propagated to backups on the rolling window.
EV
Evidence the response
The actions you took are themselves auditable, which is what an assessor will ask for.
No customer content is used to train any model, ours or a provider's. Zero-retention terms are a condition of being on the approved model list, and a model that cannot offer them is not added. See Responsible AI for the list and the policy.
We are a data intermediary for the content your crews process, which means we act only on your documented instructions. If you ask us to do something with that content that your own obligations do not permit, the answer is no, and the DPA says so in writing.
Trust Centre · Sector alignment

Aligned with MAS guidance. Not certified by anyone, because nobody certifies this.

MAS does not certify, approve or endorse vendor software. Any vendor telling you otherwise is either confused or hoping you are. What we can do is show you, control by control, how KrewOS is designed to support a regulated entity's obligations — and let you audit that mapping yourself.

Mapping reviewed against published MAS guidance as at 14 Aug 2026. Reviewed quarterly and on material change.

KrewOS is not certified, approved, licensed or endorsed by the Monetary Authority of Singapore. Regulatory obligations — including technology risk management, outsourcing and third-party risk assessment, and any notification duties — remain those of the licensed entity. Where this page says "supports", it means the product provides a mechanism you can use as part of discharging an obligation that stays yours.

Technology risk management

Mapped to the themes in the MAS Technology Risk Management Guidelines. Each row states the mechanism, and where the boundary of our responsibility sits.

TRM themeWhat KrewOS providesWhere the boundary is
Technology risk governanceNamed component owners, verification tiers, release approval workflow and an immutable record of who promoted whatYour risk appetite and approval thresholds are yours to set
System development lifecycleImmutable releases with locked dependencies, evaluation gates that block promotion, and shadow and canary release modesYour change advisory process governs when a release is promoted
Access controlRBAC aligned to platform personas, SSO and MFA, SCIM lifecycle, segregation of duties on dual approval, quarterly access review reportingYour directory is the source of truth for identity
Cryptography and key managementTLS 1.3 and AES-256, customer-managed keys on the Regulated tier, credentials held as encrypted references and injected at the call boundaryCMK rotation policy is yours to operate
Audit trail and loggingImmutable, append-only, exportable end-to-end trace covering run, node, model call, retrieval, tool, approval and costRetention beyond 7 years by agreement
Availability and recovery99.9% Control Plane availability committed under contract and remedied by service credit when missed; RPO ≤ 15 minutes and RTO ≤ 4 hours as targets; quarterly rehearsed restores with recorded resultsYour own BCP must account for the platform being unavailable
Incident management24-hour notification from confirmation, written post-mortem within 10 business days, public status historyRegulatory notification is the licensed entity's duty
Cyber security operationsAnnual third-party penetration testing plus release-triggered tests, dependency and container scanning, tamper-evident logging with 400-day retentionTesting of your own configuration and connectors is yours
Data loss preventionConfigurable detection and redaction before content reaches a model provider, with the redaction map held in-regionClassification rules are yours to define

Outsourcing and third-party risk

What an assessor needs when they treat KrewOS as a service provider. Every item here is available without a sales conversation, most of it on this site.

DD

Due diligence pack

Corporate details, financial standing, insurance certificate, security posture, subprocessor register and business continuity summary, assembled for a third-party risk assessment.

AUD

Audit rights

The Regulated tier includes contractual audit and inspection rights, including regulator access, and an annual assurance meeting with your risk function.

SUB

Subprocessor control

Full published register with 30 days' notice before any addition and a contractual objection window. Material subprocessors are named, not described as "cloud providers".

EXT

Exit and portability

Export the complete engineering repository at any time — manifests, components, schemas, prompts you own, policies, evaluations and deployment files — plus a machine-readable audit export.

CON

Concentration risk

Model provider diversity is a first-class configuration: model profiles support fallback chains across providers, and BYOK lets you keep your own contractual relationships.

LOC

Location of processing

Singapore only on managed tiers, with the Customer VPC, Hybrid and Private options where your assessment requires processing inside your own perimeter.

FEAT principles

Fairness, Ethics, Accountability and Transparency, as set out in the MAS principles and elaborated through the Veritas work. These map unusually well, because the product was designed around the same problem.

PrincipleMechanism in KrewOSEvidence you can show
FairnessEvaluation suites include disputed and edge cases; where sources of comparable authority disagree, both positions are carried forward rather than one being silently selectedEvaluation results by case class, conflict-surfacing records
EthicsNo autonomous high-impact actions; approval gates are compiled in, not configured on trust; abstention below the evidence floor is the default failure modeCompiler proof output, abstention rate by crew
AccountabilityEvery approval, rejection and edit is an immutable Correction Record tied to a named individual, a run, a release and a component versionAudit export with named reviewers and timestamps
TransparencyEvery claim carries its sources with authority tier and date; every node run records the exact component version, model profile, prompt version, tools, knowledge and policies usedEvidence records, end-to-end run trace

Legal practice and professional conduct

For law firms the analogous questions are professional conduct, confidentiality and privilege rather than prudential regulation. The position is the same in shape: the platform supports the professional, and the professional remains accountable.

1
No legal advice
KrewOS does not give legal advice and does not replace a qualified professional. Regulated outputs stay at 100% human review permanently and cannot be graduated out of it.
2
Privilege and confidentiality
Per-matter access control, deterministic privilege screening, and an audit trail that shows who saw what and when.
3
Conflicts
Conflict screening runs as a deterministic gate at matter intake, before any substantive work is scheduled.
4
Supervision
The named approver on every regulated output is a real, identified person, recorded immutably. That is the sentence a firm needs to be able to say.

What we will not say

Banned claims

These phrases appear nowhere on this site, in any proposal, or in any answer a salesperson gives you. If you hear one, it is wrong and we would like to know.

MAS certifiedMAS approvedregulator approvedPDPA compliantfully autonomousAI employeeno hallucinationsguaranteed correct

What we say instead: aligned with named guidance, designed to support your obligations, progressive autonomy, abstains below its declared evidence floor.

See the certification position
Trust Centre · Subprocessors

Every entity that touches your data, named.

Nine subprocessors, each with the purpose, the data categories it can see and the region it processes in. We add none without 30 days' written notice and a contractual objection window. A vendor that lists "cloud infrastructure providers" instead of names is not giving you a register.

Register version 11 · Effective 01 Aug 2026 · Last change: model provider added 12 Jun 2026

Current subprocessors

9 entitiesv11 · 01 Aug 2026
EntityPurposeData categoriesProcessing regionClassAdded
Cloud infrastructure provider — Singapore regionCompute, storage, managed database, object storageAll customer content and metadata, encrypted at restSingaporeMaterialMar 2025
Model provider A — Singapore endpointInference through KrewOS-managed keysPrompt and completion content, zero retentionSingaporeMaterialMar 2025
Model provider B — Singapore endpointInference and fallback routingPrompt and completion content, zero retentionSingaporeMaterialJun 2026
Managed vector searchEmbedding index for Knowledge PacksEmbeddings and document identifiers, no plaintextSingaporeSignificantMay 2025
Log and telemetry platformOperational and security loggingMetadata, identifiers, no document contentSingaporeSignificantMar 2025
Transactional email serviceVerification codes, notifications, approval alertsName, work email, notification subject linesSingaporeLimitedMar 2025
Payment processorCard payment and invoicingBilling contact, payment token; no card data held by usSingaporeLimitedApr 2025
Support ticketingCustomer support correspondenceName, work email, ticket content you supplySingaporeLimitedMar 2025
Status and incident communicationsStatus page and incident notification, hosted separately from the platformSubscriber email onlySingaporeLimitedMar 2025

Change history

Retained for the life of the register
DateChangeNotice givenObjections
12 Jun 2026Model provider B added for fallback routing and provider diversity30 daysNone received
04 Mar 2026Managed vector search moved to a Singapore-resident deployment30 daysNone received
18 Nov 2025Former analytics subprocessor removed; function brought in-houseNot required
22 Apr 2025Payment processor added ahead of first paid contracts30 daysNone received

Subscribe to changes

Free
Used only for subprocessor change notices. No marketing, ever.
30d

Advance notice

Thirty days' written notice before any subprocessor is added or its scope materially widened, sent to your registered data-protection contact and to every subscriber on this page.

OBJ

Objection window

You may object on reasonable data-protection grounds within the notice period. If we cannot resolve the objection, you may terminate the affected service without penalty.

DD

Vendor due diligence

Every subprocessor is risk-tiered and reviewed annually. Material subprocessors are contractually bound to protections no less protective than those in our DPA with you.

"Material" means the subprocessor can access customer content. "Significant" means it can access derived data or metadata but not document content. "Limited" means it touches only account or contact data.
Trust Centre · Certifications & assurance

Nothing here is certified yet. Here are the dates.

ISO/IEC 27001 and SOC 2 Type II are both in progress. Neither is achieved, and we will not describe them as achieved, imply it with a badge, or say "certification-ready" and hope you read it as certified. This page is the least flattering page on the site and it is deliberately the one we point buyers at first.

Status as at 14 Aug 2026. Updated within five business days of any change to a milestone.

Certification status

0 achieved2 in progress
FrameworkStatusWhere we areAssessorTargetEvidence available now
ISO/IEC 27001:2022In progressISMS documented and operating; internal audit complete; Stage 1 audit booked for October 2026Accredited certification body, engagedQ1 2027Statement of Applicability, internal audit report, under NDA
SOC 2 Type IIIn progressType I readiness assessment complete; 6-month observation window opened 01 Jul 2026Independent CPA firm, engagedQ2 2027Readiness assessment summary, under NDA
Third-party penetration testCompleteAnnual full-scope test completed May 2026; all high findings remediated and retestedIndependent security firm, SingaporeNext: May 2027Summary letter, under NDA
Release-triggered testingOperatingTargeted test on any change to the effect compiler, the secrets gateway or the permission modelIndependent security firmContinuousCadence attestation, under NDA
CAIQ v4 / SIG-litePublishedPre-answered and refreshed quarterly, so your questionnaire is mostly answered before you send itSelf-assessmentRefreshed Jul 2026Full document, under NDA
ISO/IEC 42001 (AI management)EvaluatingUnder assessment as the natural successor once 27001 is certified. No commitment made.Not committed
MAS certificationDoes not existMAS does not certify, approve or endorse vendor software. No vendor holds this. See the alignment page for what can honestly be said.n/a

Why we publish it this way

Because the alternative fails at exactly the moment it matters. A badge that turns out to be aspirational is discovered during your audit, not during your procurement — and by then it is your problem as much as ours.

1

An overstated claim is a contract problem

Certification language ends up in an MSA, a board paper and a regulatory filing. Saying "in progress" today costs a deal occasionally. Saying "certified" today costs a customer permanently.

2

Controls exist before certificates do

A certificate attests that controls were operating during an observation window. The controls themselves are documented in full on the security page and can be assessed today, certificate or not.

3

How a vendor handles this predicts everything

This is the cheapest available signal of how a supplier will behave when the next inconvenient fact arrives — during an incident, during an audit, or on the day a model provider changes its terms.

Penetration testing

All high findings closed
TestDateScopeHighMediumState
Annual full scopeMay 2026Platform, API, tenant isolation, secrets gateway27Remediated, retested
Release-triggeredMar 2026Effect compiler rewrite03Remediated
Release-triggeredNov 2025Permission model and impersonation flow14Remediated, retested
Annual full scopeApr 2025Platform and API311Remediated, retested

Vulnerability disclosure

Safe harbour
Contact
security@krewos.ai
Policy
/.well-known/security.txt
Acknowledgement
1 business day
Triage
48 hours
Critical fix target
7 days
High fix target
30 days
Disclosure
Coordinated, agreed with you
Credit
Named, if you want it
Bug bounty
Private programme only
A public bounty programme is deferred until the disclosure process has run a full year without a backlog. Running a bounty you cannot service is worse than not running one.
One more thing we will not do: we do not accept a badge or listing from a trust-marketplace product and present it as an independent assessment. Where an assessment is a self-assessment, this page labels it a self-assessment.

Get the assurance evidence

Statement of Applicability, internal audit summary, penetration-test summary letter, readiness assessment and the pre-answered CAIQ, all under a click-through NDA.

Open the document portal

Track the milestones

Subscribe and we will notify you when a certification milestone moves — including when it slips, which is the notification that actually matters.

Subscribe on the status page
Trust Centre · Document portal

The security pack, in about ninety seconds.

Enterprise deals stall for weeks waiting on a DPA and a penetration-test letter. Accept a click-through NDA here and the whole pack is available immediately — no sales call, no chasing, no "let me check with the team".

The NDA is mutual, two pages, and governs only the documents in this portal. You can read it in full before accepting.

1 · Who you are
2 · Accept the NDA
3 · Choose documents
4 · Download

Step 1 · Identify yourself

Complete
Free-domain addresses are not accepted for NDA-gated documents.
If you are not authorised, we email the NDA to your nominated signatory instead of blocking you here.

Step 2 · Mutual non-disclosure agreement

NDA v3.1
MUTUAL NON-DISCLOSURE AGREEMENT — v3.1
Between wGrow Technologies Pte Ltd (Singapore) and the Recipient
named above, effective on acceptance.

1. Scope.  Applies solely to the documents obtained through the
   KrewOS trust document portal.
2. Purpose.  Evaluation of KrewOS for possible procurement.
3. Term.  Two years from acceptance.
4. Permitted disclosure.  Employees, professional advisers and
   your regulator, each on equivalent terms.
5. Mutual.  Information you disclose to us during evaluation is
   protected on identical terms.
6. Regulator carve-out.  Nothing restricts disclosure required
   by law or by a regulator with authority over you.
7. No obligation.  Acceptance creates no obligation to purchase
   and no exclusivity.
8. Governing law.  Singapore.
Clause 6 exists because a compliance officer cannot accept an NDA that would stop them answering their own regulator. Several vendors' NDAs do exactly that.

Step 3 · Choose your documents

Unlocked immediately on acceptance. Watermarked with your organisation name and the acceptance date — visibly, so nobody is surprised later.

DocumentVersionUpdatedPagesAccessWho usually asks
Data Processing Agreementv2.301 Jul 202614NDADPO, general counsel
Service Level Agreementv1.801 Jul 20266NDAProcurement, operations
Penetration test summary letterMay 202604 Jun 20263NDASecurity, risk
Architecture & security overviewv4.022 Jul 202628NDACTO, architects
Pre-answered CAIQ v4Q3 202610 Jul 202642NDASecurity assessment teams
Pre-answered SIG-liteQ3 202610 Jul 202631NDAThird-party risk
Business continuity & DR summaryv2.118 Jun 20269NDAOperational resilience
Insurance certificate2026/2701 Apr 20262NDAProcurement, legal
MAS controls mappingv3.014 Aug 202619NDACompliance, MLRO
Master agreement / terms of servicev5.201 Jul 202622OpenAnyone — no NDA needed
Subprocessor registerv1101 Aug 20264OpenAnyone — published here
Acceptable use policyv2.001 Jul 20265OpenAnyone
NOW

Immediate, not "within 5 days"

Acceptance unlocks the pack in the same session. The most common reason a security review takes six weeks is that the first document took three.

UPD

Update notifications

When a document you downloaded is revised, we tell you what changed and why. Silent revisions to a DPA are how procurement teams lose trust in a vendor.

LOG

We log the access

Acceptances and downloads are recorded, and we say so here rather than in a footnote. If your firm's policy is that we should not, ask and we will send the pack by another route.

Accepting the NDA also flags your evaluation to a solutions engineer, who will contact you within one business day. If you would rather they did not, say so in the role field and nobody will call.
Trust Centre · Responsible AI & model policy

Governance is a mechanism here, not a statement of values.

Most responsible-AI pages are a list of principles nobody can verify. This one describes five mechanics that are enforced by the compiler and the runtime — outside the model prompt, where a prompt injection cannot reach them — and tells you how to check that each is actually operating in your own tenant.

Model policy reviewed monthly. Approved model list current as at 14 Aug 2026.

Five mechanics

Each one has a failure mode it exists to prevent, and each is observable in your own audit trail.

1 · Abstention below the evidence floor

Enforced

Every evidence set is scored for sufficiency against the specific claim it is asked to support. Each Crew Template declares an evidence floor. Below it, the crew returns a structured insufficiency result naming what could not be established and which sources would resolve it — it does not produce a lower-confidence answer and hope a reviewer notices.

GAP
Abstentions are routed, not logged
They go to a human knowledge-gap queue and are reported separately from failures, because an abstention means a missing source, not a broken crew.
CNF
Conflicts are carried forward
Where sources of comparable authority disagree, both positions reach the reviewer. The system does not silently pick one.
STL
Staleness propagates
When a source expires or materially changes, every artefact that relied on it is identified and its owners are notified.

Verify it yourself

Abstention rate
Per crew, in-product
Knowledge-gap queue
Live, per project
Evidence floor
Declared in the manifest
Sufficiency score
On every evidence set
Conflict records
In the audit export
Staleness notices
To the artefact owner
Twenty-one per cent of the Aquaculture Pack's evaluation suite consists of cases where the only correct behaviour is to decline. Abstention is measured, not assumed.

2 · Named human accountability

Immutable

Every approval, rejection and edit is an immutable Correction Record tied to a named individual, a run, a release and a component version. Human decisions are append-only: corrections supersede, they never rewrite. Shared logins defeat this, which is why reviewer seats are cheap — it is a governance decision disguised as a pricing one.

Those corrections are expert-confirmed and promoted into the crew's evaluation suite, so the suite grows out of real disputed cases from your own work.

3 · No autonomous high-impact actions

Compiled in

Tools read or compute. Actions cause external side effects and require an idempotency key, declared compensation behaviour and, where configured, human approval. The compiler statically proves before a release exists that no path runs from untrusted input to an external Action without an intervening approval gate.

If the property does not hold, there is no release to deploy. This is a proof, not a policy document, and it cannot be switched off for convenience.

4 · Bounded loops and budgets

Fails closed

Iteration limits are declared at design time; the editor refuses to let you test a crew with an unbounded loop, a missing exit path or an orphan node. Revision loops in production crews are bounded — three iterations in Content Studio, for example — and exhausting the bound escalates to a human rather than continuing.

Soft budget limits degrade the model tier or concurrency first. Hard limits fail closed before spending. Per run, per project, per tenant.

5 · Evaluation gates and earned autonomy

Reverts automatically

Every crew launches at 100% human review. It graduates to risk-weighted sampling only on measured accuracy at a published confidence bound, and reverts automatically on breach. Sampling is risk-weighted, never uniform, and reviewer behaviour is itself measured — a sampling regime is only as sound as the reviews that calibrate it.

Regulated outputs — legal advice, financial statements, anything with a professional signature — stay at full review permanently and cannot be graduated out of it. That is a property of the Crew Template, not a setting an administrator can change on a busy Friday.

Model policy

A model profile declares which models may be used, in which jurisdictions, with what retention terms and what fallback behaviour. The runtime refuses to route outside the profile, so the policy is enforced by configuration rather than by an operator remembering it.

PolicyPositionHow it is enforced
Training on your dataNeverNo customer content is used to train any model, ours or a provider's. Contractual zero-retention terms are a condition of being on the approved list.
Approved model listMaintained centrallyModels are added only after residency, retention, evaluation and cost review. A model not on the list cannot be selected in a profile.
Endpoint jurisdictionSingapore-residentThe profile declares permitted jurisdictions; the gateway refuses to route elsewhere.
Bring your own keySupported on all tiersYour provider contract, your negotiated terms. Credentials held as encrypted references, injected at the call boundary, never in a prompt or a log.
Private and self-hosted modelsSupportedPoint the gateway at a model you host, including inside a disconnected environment.
Model change managementPinned per releaseA release pins its model profile. A provider deprecation triggers a re-evaluation against the crew's suite before the substitute is permitted.
Fallback chainsExplicitFallbacks are declared and evaluated, not implicit. A fallback that has not passed the suite is not a fallback.
We do not train foundation modelsOut of scopewGrow governs access to approved models. Building them is somebody else's business.
BIA

Bias and evaluation

Evaluation suites include disputed and edge cases by construction, and Pack publishers must justify suite adequacy for the declared risk level before verification. Results are reported by case class, not as a single number.

ESC

Incident escalation

A crew producing materially wrong output is an incident with the same process as a security event: contain by reverting autonomy or the release, notify affected tenants, write it up, and add the case to the evaluation suite.

NO

What we deliberately do not build

No self-modifying production crews. No unrestricted component marketplace. No autonomous high-impact actions. No claim that the system is right — only a record of what it relied on and who agreed.

Trust Centre · Status & uptime

One component degraded. Everything else operational.

Component and region status, uptime history and every incident we have had, including the ones that were our fault and the ones that were a model provider's. Hosted on infrastructure separate from the platform, because a status page that goes down with the thing it reports on is decoration.

Updated every 60 seconds · 14 Aug 2026, 16:42 SGT · Availability committed at 99.9% monthly on the shared Control Plane, where the contract carries it

Overall
Partially degraded
30-day uptime
99.98%
90-day uptime
99.97%
12-month uptime
99.95%
Open incidents
1
Next maintenance
23 Aug 2026

Current component status

Singapore region
ComponentStatus30-day uptimep95 latencyNote
Control Plane — APIOperational100%86 ms
Control Plane — StudioOperational100%142 ms
Execution Plane — SingaporeOperational99.99%Run queue depth normal
Model Gateway — provider ADegraded99.71%4,180 msUpstream provider latency; fallback chain engaged
Model Gateway — provider BOperational99.98%910 msAbsorbing failover traffic
KrewOS HubOperational100%74 ms
Knowledge indexingOperational99.96%Index lag under 30 s
Approval & notificationsOperational100%
Audit exportOperational100%
Billing & credit ledgerOperational100%

Incident history

Post-mortems published within 10 business days
DateIncidentImpactDurationCauseState
14 Aug 2026Provider A inference latencyRuns on provider A slowed; fallback chain engaged automaticallyOngoingUpstream providerMonitoring
28 Jun 2026Approval notifications delayedEmail approval alerts delayed up to 46 minutes; in-app queue unaffected1h 12mOur fault — queue misconfiguration after a deployResolved
11 May 2026Knowledge indexing backlogNewly uploaded documents not retrievable for up to 2 hours; existing knowledge unaffected2h 04mOur fault — embedding worker scaling limitResolved
02 Apr 2026Provider B regional outageProfiles pinned to provider B failed over; 14 runs paused and resumed automatically38mUpstream providerResolved
19 Feb 2026Control Plane API errorsElevated 5xx on the catalogue API; running crews unaffected, Studio degraded27mOur fault — database connection exhaustionResolved
07 Jan 2026Scheduled maintenance overrunPlanned 30-minute window ran to 71 minutes; runs queued and drained without loss71mOur fault — migration slower than rehearsedResolved

Subscribe

Free
Webhooks post the same payload we use internally, including the incident identifier.
Certification milestone notices go out through this list too — including when a target date slips, which is the one worth subscribing for.

Monthly attainment, Control Plane

Committed 99.9%
MonthUptimeDowntimeIncidentsCommitment met
August 2026 (to date)100%0m0Yes
July 2026100%0m0Yes
June 202699.93%30m1Yes
May 202699.95%22m1Yes
April 202699.99%4m1Yes
March 2026100%0m0Yes
February 202699.94%27m1Yes
January 202699.84%71m1No — 10% credited
This table is the published attainment, and it is the figure the service credit below is computed from — not a summary of it. It is measured by three probes operated outside the platform, on the infrastructure that hosts this page, because a platform that measures its own outage will always find it shorter than you did.

Maintenance & conventions

23
23 Aug 2026 · 02:00–03:00 SGT
Database version upgrade. Studio read-only for up to 15 minutes; running crews continue on their pinned release.
Scheduled
WIN
Standard window
Sundays 02:00–04:00 SGT, announced at least 7 days ahead. Regulated-tier tenants may nominate an alternative window.
CRD
Service credits
Issued automatically against a contract that carries the commitment, on the published schedule below. You do not have to claim them, and the January 2026 credits went out without anyone asking.
OUR
Whose fault it was
Every incident row says whether the cause was ours or a provider's. Model-provider outages get blamed on us anyway; publishing the distinction is how that argument gets settled.

What a missed month is worth

The schedule is published because a commitment without a stated remedy is a sentiment. It applies to contracts that carry the availability commitment; it is not a property of every plan, and we would rather print that limit than let you assume otherwise.

Service credit schedule

Committed 99.9%One tier applies per month
Attainment in the monthService creditWhat it is
Below 99.9%, at or above 99.5%10% of the baseJanuary 2026 fell here at 99.84%
Below 99.5%, at or above 99.0%25% of the baseNever reached
Below 99.0%50% of the baseNever reached · also counts toward termination
Never more than half. Exactly one tier applies in any month, so a month's credit can never exceed half that month's base. Where a contract commits a figure other than 99.9%, the same three tiers sit at the committed figure, 0.4 points below it and 0.9 points below it — a higher commitment does not buy a breach that reaches no remedy.
Three bad months and you can leave. Served below 99.0% in any three months of a rolling twelve and you may terminate without penalty. That figure is absolute — it does not move with the figure your contract commits, and the right stands alongside the credit rather than instead of it.

What the credit is measured on

One base would pay somebody nothing. A percentage of subscription pays nothing to a firm that buys only credits; a percentage of consumption pays nothing to a firm whose subscription is most of its bill — and either collapses in exactly the month we stopped working. So the base is the greatest of three figures, never their sum.

1
What you were charged for that month
Spread across the period each charge funds, so an annual invoice draws a twelfth per month rather than everything in the month it was raised.
2
What you consumed that month
Valued at the effective rate of the lots you drew on. Under BYOK this is the smaller platform figure, because platform credits are all we ever debit you.
3
Your usual volume before the failure
The mean of the three months before the run of bad months began — not months the failure has already eroded.
Capped at three times the first figure, so volume from before a downsizing cannot be recovered against an invoice a fraction of its size.
MON

It is money, not credits

The credit is applied against your next invoice. It grants no platform credits, creates no lot and carries no expiry. Paying for a broken commitment in credits that lapse before you can spend them is the appearance of a remedy rather than one.

AUT

No claim form

It is computed from the attainment published above and your own billed and metered volume, so there is nothing for you to submit and nothing for us to weigh. The month you would be chasing a claim is the month we are handling the incident.

EXI

Paid out if you leave

Any unapplied balance is discharged in cash when you leave, net of anything you then owe us, rather than lapsing. A tenant that has already gone is otherwise the one tenant a service credit pays nothing to.

The service credit is the only financial remedy for a missed availability commitment — but "only" is a statement about that commitment and nothing else. Credits consumed by a run that failed because we failed are reversed automatically on their own terms, and neither is set off against the other.
Trust Centre · Legal hub

Every agreement, versioned, with the changes written out.

The contract set in one place, each with its version, effective date and who it applies to. Superseded versions stay published — a counterparty should be able to read the terms that governed them last March without asking us for a copy.

Governing law: Singapore · legal@krewos.ai · Registered: wGrow Technologies Pte Ltd, Singapore

Contract set

12 documentsreviewed 01 Jul 2026
DocumentVersionEffectiveApplies toNegotiableAccess
Master Services Agreementv5.201 Jul 2026All paid tiersRegulated tierOpen
Terms of Service (self-serve)v5.201 Jul 2026Trial and PracticeNoOpen
Data Processing Agreementv2.301 Jul 2026All tiersRegulated tierNDA
Subprocessor addendumv1101 Aug 2026All tiersNoOpen
Service Level Agreementv1.801 Jul 2026Contracts carrying the availability commitmentRegulated tierNDA
Acceptable Use Policyv2.001 Jul 2026All tiersNoOpen
Pack Licence Termsv3.101 Jun 2026Licensed Pack holdersVolume termsOpen
Publisher Agreementv1.201 Jun 2026Pack and component publishersYesOpen
Privacy Policyv4.001 Jul 2026Everyone, including site visitorsNoOpen
Cookie Policyv2.101 Jul 2026Site visitorsNoOpen
Support & Escalation Policyv1.501 Jul 2026All paid tiersNoOpen
Vulnerability Disclosure Policyv1.312 Mar 2026Security researchersNoOpen

Change log

Material changes notified 30 days ahead
DateDocumentWhat changedMaterial
01 Aug 2026Subprocessor addendum v11Model provider B added for fallback routing and provider diversityYes
01 Jul 2026DPA v2.3Data-subject request assistance timelines tightened; deletion propagation to backups described explicitlyYes
01 Jul 2026MSA v5.2Audit and inspection rights extended to regulator access on the Regulated tierYes
01 Jul 2026SLA v1.8Service credits now issued automatically rather than on claim, paid as a billing credit against the next invoice rather than in platform credits, with any unapplied balance discharged in cash on departureYes
01 Jun 2026Pack Licence Terms v3.1Fork rights and lineage retention stated explicitly; exit position on tenant corrections clarifiedClarification
12 Mar 2026Vulnerability Disclosure v1.3Safe-harbour language broadened for good-faith researchClarification

Entity details

Legal entity
wGrow Technologies Pte Ltd
Incorporated
Singapore, 2008
Governing law
Singapore
Dispute resolution
SIAC arbitration, Singapore
Contracting currency
SGD or USD
Legal contact
legal@krewos.ai
Privacy contact
dpo@krewos.ai
Security contact
security@krewos.ai
Regulated-tier customers may contract on their own paper. We will tell you within five business days whether we can work from it, rather than discovering an impasse in week six.

Three positions worth reading before you ask

These are the clauses most often negotiated, stated here so you can decide whether there is anything to negotiate.

EXT

What you keep on exit

Your manifests, components, configurations, knowledge, Correction Records, evaluation additions and audit exports. Licensed Pack corpora and publisher IP stay with the publisher. Export works during the contract, not only at the end of it.

IP

Who owns the output

You own the artefacts your crews produce and any custom components you build. We claim no licence to your content beyond what is needed to run the service you asked for.

SUB

Change of subprocessor

Thirty days' notice, a contractual objection window on reasonable data-protection grounds, and termination of the affected service without penalty if an objection cannot be resolved.

Superseded versions of every document on this page remain available on request and are listed in the change log above. If a term that governed you has changed, you should be able to read both versions side by side without involving a salesperson.
Pricing

Priced for the work, not the seats.

A platform subscription for the governance, prepaid credits for the runs, and licensed Packs for the domain expertise. Bring your own model keys and you pay us for the platform only.

All figures in Singapore dollars, illustrative. 1 credit = S$0.01, published and unchanging. Reviewer seats are deliberately cheap.

Credit value
S$0.01 per credit
Meters
Platform + model, one wallet
BYOK
Model meter 0
Data region
Singapore
Billing
Card or invoice, SGD
Trial
Free / 30 days
Evaluate the whole platform without talking to anyone.
  • 5,000 credits total, not monthly
  • 3 builder · 5 reviewer seats
  • Studio, Hub and Evaluation Lab
  • Development environment
  • No production deploy
  • No licensed Packs, no SSO
Start free
Practice
S$690 / mo
One team running one workflow in production.
  • 60,000 credits / month
  • 5 builder · 20 reviewer seats
  • Dev + Production environments
  • Audit export, 90-day retention
  • Email support, next business day
  • No SSO, no review sampling
Start free, then upgrade
Professional Most chosen
S$2,400 / mo
Several crews, several teams, real governance obligations.
  • 250,000 credits / month
  • 15 builder · 100 reviewer seats
  • SSO — OIDC and SAML
  • Progressive autonomy and review sampling
  • Shadow and canary releases, dual approval
  • 99.9% availability, committed in the contract
Talk to us
Regulated
From S$9,500 / mo
Licensed entities with residency, isolation or key-custody requirements.
  • 1,000,000+ credits, negotiated
  • Seats by agreement, unlimited reviewers
  • Customer-managed keys
  • Cloud Dedicated, customer VPC, hybrid, private
  • Negotiated availability commitment, named CSM, 24×7 P1
  • Negotiated DPA, legal hold, extended retention
Contact sales
Annual contracts are billed at ten months for twelve. Every tier can bring its own model keys, including Trial — BYOK is not an enterprise upsell.

What a credit is, in two sentences

One KrewOS credit is one unit of metered platform consumption, prepaid and drawn down as your crews run. One credit is one Singapore cent, so a thousand credits is ten dollars and you can do the arithmetic without us.

PLT

Platform credits — always charged

Run orchestration, node execution, retrieval and reranking, evidence storage and indexing, evaluation runs, human-task management, audit retention and artefact storage. This is the meter that never goes to zero, because governance is the product.

MDL

Model credits — zero under BYOK

Inference through KrewOS-managed provider keys, at published per-model rates. Point us at your own provider account and this meter reads zero for every run: your provider invoices you directly at your negotiated rates.

WLT

One wallet, two meters

Both meters draw from the same prepaid balance, shown as a single figure in the top bar of your workspace with days of runway attached. Every run's settlement is itemised by node in the ledger.

Worked example — one document review

24-page tenancy agreement
NodePlatformModel
Jurisdiction router24
Evidence Research Pod · 4 agents, 11 retrievals3496
Drafting6140
Adversarial Reviewer688
Regulatory Review Pod · deterministic gates1812
Human task, audit and storage120
Total credits78340
At listS$0.78S$3.40
With BYOKS$0.78your provider

Already have provider contracts? Keep them.

With BYOK, model consumption is billed by your provider directly and your KrewOS credits cover only platform runtime — orchestration, retrieval, evidence, evaluation, governance and audit. Monthly credit burn typically falls by 60–75%, and you keep your negotiated model rates and your existing zero-retention terms.

Managed keys, 400 matters / month
167,200 credits
BYOK, same 400 matters
31,200 credits
Reduction in credit burn
81%
Matters covered by a Professional allowance
~3,200 / month
BYOK does not lower your subscription. What it buys is headroom and rate control — and, for most regulated buyers, a model contract their risk committee has already signed off.
Open the estimator →

Everything, compared

The line that matters is usually not the price. It is whether the tier gives your compliance function what it needs to sign the thing off.

CapabilityTrialPracticeProfessionalRegulated
Commercials
PriceFree, 30 daysS$690 / moS$2,400 / moFrom S$9,500 / mo
Annual equivalentS$6,900S$24,000Annual contract
Included credits5,000 total60,000 / mo250,000 / mo1,000,000+ / mo
Top-up bundles volume rates committed use
PaymentCardCard or invoiceInvoice, PO, SGD or USD
Seats and scope
Builder seats3515By agreement
Reviewer seats520100Unlimited
Workspaces / Projects1 / 11 / 55 / unlimitedUnlimited
EnvironmentsDevelopment onlyDev + ProductionDev + Test + ProductionAll, plus dedicated
Production deployment
Build and catalogue
Studio, Assemble and Engineer modes
Hub — verified components
Private tenant catalogue
Licensed PacksLicensed separatelyLicensed separatelySeparately, volume terms
Git export and eject
Governance
Evidence, abstention and sufficiency scoring
Evaluation Lab and release gates
Progressive autonomy — review sampling
Shadow and canary releases
Dual approval on high-risk Actions
Audit export90-day retentionConfigurable retentionExtended retention, legal hold
Security and deployment
SSO — OIDC and SAML
BYOK — bring your own model keys
Customer-managed encryption keys
Data regionSingaporeSingaporeSingaporeSG, dedicated, VPC, hybrid, private
Availability commitmentNot carriedNot carried99.9% Control Plane, in the contract99.9% or higher, negotiated
Service credit if we miss it10 / 25 / 50% of the month's baseSame schedule, boundaries derived from the committed figure
DPAClick-throughStandardStandardNegotiated
SupportDocs and communityEmail, next business dayPriority 8×5, 4h P124×7 P1, named CSM, QBR

Packs and add-ons

Packs are licensed annually and separately from the platform, because the domain IP has its own publisher and its own maintenance cadence. Maintained Packs carry dated currency assertions and notify entitled tenants when a source changes.

KrewOS Pack licences

PackAnnual licenceMaintainedWhat is inside
Singapore Legal PracticeS$18,000QuarterlyJurisdiction routing, clause libraries, privilege policies, LawCrew templates, evaluation datasets
MAS Financial ComplianceS$24,000QuarterlyControls mapping, reconciliation policies, dual-approval templates, dashboards
Aquaculture OperationsS$12,000Half-yearlySpecies and regional knowledge, water-chemistry rules, telemetry connectors, escalation routing
SG Tender ResponseS$9,000QuarterlyTender relevance classification, requirement extraction, response templates, compliance checklist

Add-ons

Additional builder seat
S$95 / mo
Additional workspace
S$250 / mo
Extended audit retention, 7 years
S$400 / mo
Managed Crew Operations
from S$3,500 / mo
Implementation
from S$25,000
Private deployment engagement
Quoted
Top-up bundles
50,000 credits
S$500
250,000 credits
S$2,250
1,000,000 credits
S$8,000
5,000,000+
Committed use

Bundles are valid twelve months from purchase.

Questions we would rather answer here than on a call

What happens when credits run out mid-run?

The run is never killed. Credits are reserved at admission and settled at each checkpoint. If the balance falls short, the crew stops issuing new side-effect Actions, finishes the checkpoint it is on, and parks in awaiting_credit with a 72-hour grace window. Top up and it resumes from the checkpoint automatically.

Do credits roll over?

Plan-included credits reset monthly and do not roll over. Purchased top-up bundles are valid for twelve months. Annual plans roll over up to one month's allowance.

Can I cap spend?

Yes — hard caps per run, per project and per tenant. Against a soft cap the runtime degrades the model tier or concurrency before it fails. Against a hard cap it fails closed, before spending. Alerts fire at 50%, 80% and 95%.

Can I deploy to production on trial?

No. Trial is a development environment with 5,000 credits and 30 days. This is deliberate: it protects the value of the paid tiers, and a production deployment with no SLA behind it is not something we want in a regulated firm.

What counts as a seat, and are reviewers charged?

A builder seat can create and edit crews, releases and knowledge. A reviewer seat sees only the Approval Workbench and the runs assigned to them. Reviewers are included in generous numbers and never metered per approval — shared logins would destroy the named-accountability trail the product exists to produce.

Can I move regions later?

No. A workspace's data region is chosen at creation and is immutable. Moving is a migration for both parties, so we make you choose deliberately rather than discover it in year two.

What is in a Pack licence?

Crew Templates, Knowledge Packs, deterministic policy packs, evaluation datasets and dashboards for one vertical, licensed annually to one tenant. A Maintained Pack adds dated currency updates and change notifications on the published cadence.

What is the SLA?

99.9% monthly Control Plane availability, committed in the contract rather than attached to a plan. Miss it and you are credited automatically on a published schedule — 10% of the month's base below 99.9%, 25% below 99.5%, 50% below 99.0% — as money against your next invoice, never as expiring credits. Three months below 99.0% in a rolling twelve and you can leave without penalty. Recovery targets are RPO ≤ 15 minutes and RTO ≤ 4 hours on the standard tier, published as targets and carrying no credit.

How does BYOK billing work?

You register your provider credentials as encrypted secret references. Runs route inference to your account, your provider invoices you, and the model meter on your KrewOS wallet reads zero. Platform credits are charged as normal.

Do evaluation runs consume credits?

Yes, and we say so up front. Testing is real work — retrieval, inference and scoring all happen. Failed runs consume the credits used up to the failure point; runs that fail due to a KrewOS fault are refunded automatically.

Can I pay by invoice in SGD?

Yes on Professional and Regulated, with purchase-order references and thirty-day terms. Practice is card only. USD invoicing is available on Regulated.

What happens to my data and manifests at the end of a contract?

You can export a complete engineering repository at any time during the contract, including manifests, schemas, prompts, policies, evaluation suites and audit records. After termination the workspace is read-only for 30 days, then deleted on the retention schedule. Nothing is deleted silently.

Try it yourself

5,000 credits, 30 days, no card and no production deployment. Enough to build a crew from a template, run it on your own sample documents, read the evidence behind a claim and export the audit trail.

Start free

Bring your compliance team

45 minutes with a solutions engineer using your jurisdiction and your documents, with the residency, retention and audit questions answered on the call rather than in a questionnaire three weeks later.

Book a demo Compare deployment options
Pricing · Credits

Credits, explained without the small print.

Consumption pricing only works if you can predict the bill. So here is the whole mechanism: what a credit buys, which meter charges you, how a single matter settles, and exactly what happens when the balance runs low mid-run.

One credit
S$0.01
1,000 credits
S$10.00
Prepaid
Always, never post-billed
Reserved
At run admission
Settled
At every checkpoint

What a credit is

One KrewOS credit is one unit of metered platform consumption. Credits are prepaid, drawn down as your crews run, and always visible in your wallet with a runway estimate attached. The conversion is published and does not move: 1 credit = S$0.01. We publish it because an abstract token you cannot convert to money is the single most common reason consumption pricing fails to convert.

BUY

What a credit buys

A slice of real work: a retrieval against a Knowledge Pack, a reranking pass, one node execution with its trace written, an evidence record indexed and stored, a scorer run in the Evaluation Lab, a human task opened and routed, a year of audit retention on one run.

NOT

What a credit is not

Not a seat, not an API call quota, not a token count you have to convert. Seats are licensed in the subscription. Domain assets are licensed in the Pack. Credits meter the run and only the run.

SEE

Where you see them

Balance and runway in the workspace top bar; per-run settlement itemised by node in the Cost & Outcomes screen; per-project and per-tenant burn in the ledger; and a cost-per-outcome figure computed from the same records that enforce your budgets.

Two meters, one wallet

Every run charges two meters against a single prepaid balance. The distinction matters because one of them can be switched off entirely, and the other cannot.

MeterWhat it coversManaged keysBYOK
Platform credits Run orchestration and node execution, knowledge retrieval and reranking, evidence storage and indexing, evaluation runs, human-task management, audit retention, artefact storage, effect verification and policy evaluation Charged Charged, unchanged
Model credits Inference through KrewOS-managed provider keys, at published per-model rates plus a stated margin, attributed to the node and model profile that made the call Charged Zero
Bring your own keys and your model spend leaves our bill entirely. You still consume platform credits, because orchestration, evidence, evaluation and audit are the platform. We would rather say that plainly here than have you discover it on the first invoice.

One matter, from reservation to settlement

A LawCrew document review of a 24-page tenancy agreement for Tanglin Holdings. Reservation happens once, at admission. Settlement happens at each checkpoint, against actual consumption, and the unused reservation is released the moment the run closes.

Run RUN-8F2C41 · credit ledger

crew v3.0.2managed keys
EventCheckpointPlatformModelHeldAvailable
Admission — reservation takenCP-0600248,300
Jurisdiction router settledCP-124594248,300
Evidence Research Pod settled · 11 retrievalsCP-23496464248,300
Drafting settledCP-36140318248,300
Adversarial Reviewer settledCP-4688224248,300
Regulatory Review Pod settled · deterministic gatesCP-51812194248,300
Human task opened · waiting 3 days for sign-offCP-690185248,300
Approved by S. Rajah · audit written, artefacts storedCP-730182248,300
Run closed · unused reservation released0248,482
Settled total78340S$4.18

Waiting is nearly free

Three days parked on a human task cost nine platform credits, not three days of anything. Durable runs hold committed state; they do not hold compute.

Reservation is not a charge

The 600-credit hold is sized from what this crew actually costs: its recent P90 of 521 credits, multiplied by 1.15 and rounded up. The arithmetic is published because a hold you cannot predict is indistinguishable from a charge. You are only ever charged what settles, and the remainder returns to the wallet at close. Notice that the available balance moves twice and only twice — down by the hold at admission, up by the unused 182 at close. Settling a checkpoint converts a hold into a spend, so it does not move it at all.

With BYOK, the same matter

78 platform credits — S$0.78 — and 340 model credits' worth of inference billed by your own provider at your own rates. The ledger still itemises the model calls; it just does not price them.

What happens if credits run out mid-run

This is the question that decides whether a firm can put a client matter through the platform at all. The answer is the same for every tier: a run in flight is never killed for money.

1
Reserve at admission
A run is only admitted if the wallet can cover its reservation — the crew's recent P90 run cost, never less than 8 credits, multiplied by 1.15 and rounded up to the whole credit. If it cannot, the run is rejected before it starts, with a clear message — not half-way through a client matter.
Admission gate
2
Settle per checkpoint
Actual consumption is settled at each checkpoint, so the wallet reflects reality continuously rather than at the end. A long-running matter cannot accumulate an invisible debt.
Continuous
3
Alert at 50 / 80 / 95%
Threshold notices go to the workspace administrator and the billing contact, with the current burn rate, projected exhaustion date and a one-click top-up.
Soft
4
Degrade before failing
Against a soft cap the runtime drops to a lower model tier and reduces concurrency first. It also stops issuing new side-effect Actions — nothing external is sent, filed or posted while the wallet is short.
Degraded
5
Park at a checkpoint
If the balance still cannot cover the next checkpoint, the run completes the checkpoint it is on and parks in awaiting_credit. State is committed, evidence is retained, and the reviewer queue shows the reason.
awaiting_credit
6
72-hour grace, then auto-resume
You have 72 hours to top up. The moment credits land, parked runs resume from their last checkpoint in submission order — no re-run, no duplicate Actions, no lost evidence. Idempotency keys guarantee the same external effect is never fired twice.
Auto-resume
7
After the grace window
Unresumed runs move to suspended. Nothing is deleted: the run, its state, its evidence and its audit record are retained on your normal retention schedule and can still be resumed or exported once the wallet is funded.
Suspended
Hard caps behave differently on purpose. A hard cap — per run, per project or per tenant — fails closed before spending, because a hard cap is a control you set deliberately. An empty wallet is an accident, and accidents should degrade, not detonate.
Failed runs. A run that fails consumes the credits used up to the failure point, itemised in the ledger. If the failure is attributable to a KrewOS fault — a control-plane incident, a gateway defect, a checkpoint that did not commit — the credits are refunded automatically and appear as a ledger reversal, without you having to ask.

Expiry, rollover and top-ups

Three rules, and we would rather you read them here than find them in a schedule.

Expiry policy

Credit typeValidityRolloverOn expiry
Plan-included, monthlyThe billing month NoneAllowance resets on the billing date
Plan-included, annual contractThe billing month Up to one month's allowanceRolled balance expires the following month
Purchased top-up bundle12 months from purchase FullExpires 12 months from purchase. We email you 30 days, 7 days and 1 day before
Trial credits30 days NoneExpire with the trial and cannot be topped up
Goodwill credits90 days FullExpire 90 days after we issue them, with the same notices

Drawdown order is fixed and shown in the ledger: plan allowance first, then the oldest expiring bundle, then the newest. You are never silently spending the balance that lasts longest.

Controls

Auto top-up
Optional, off by default, with a monthly ceiling you set
Per-run cap
Rejects admission above the envelope
Per-project cap
Monthly, resets with the billing cycle
Per-tenant cap
Hard ceiling, fails closed
Threshold alerts
50%, 80%, 95% to admin and billing

How BYOK changes the maths

The same 400 matters a month, priced both ways. Nothing about the platform behaves differently — only the meter does.

LineKrewOS-managed keysBYOK
Platform credits per matter7878
Model credits per matter3400
Credits per month at 400 matters167,20031,200
Credit value drawnS$1,672S$312
Against a Professional allowance of 250,000Covered · 82,800 spareCovered · 218,800 spare
Matters per month before a top-up~598~3,205
Model inference billed byKrewOS, at published ratesYour provider, at your rates
Where the keys livePlatform-managed secret storeTenant-managed encrypted secret reference

What BYOK actually buys you

At a volume inside your allowance, BYOK does not reduce this month's invoice — it buys headroom, rate control and a model contract your risk committee has already reviewed. Above the allowance it reduces the bill directly, because top-ups are the only variable line.

What it does not change

Governance is identical. Evidence, sufficiency scoring, effect declarations, approval gates, evaluation and audit run the same way against your keys as against ours, and the ledger still attributes every inference call to a node, a model profile and a prompt version.

Work out your own number

Enter your crew, your volume and your own manual baseline. We do not supply a default baseline — a vendor-supplied one makes the return look manufactured.

Open the estimator Book a demo with these numbers
Pricing · Estimator

Build the business case before you talk to us.

Enter your crew, your volume, your review posture and your own manual baseline. The estimator returns credits per month, the tier that covers them, cost per outcome unit against your baseline, and payback in months.

We do not supply a default manual baseline. A vendor-supplied one makes the return look manufactured, and buyers are right not to believe it.

Your inputs

Draft saved
The work
Requires the Singapore Legal Practice Pack — S$18,000 / year, included below.
Set by the Crew Template. Every cost figure below is per outcome unit.
Governance posture
Legal outputs stay at 100% permanently. Sampling is available on Professional and above for crews that qualify.
Your manual baseline
Leave blank if you intend to implement in-house.
Credits / month
167,200
31,200 platform · 136,000 model
Credit value
S$1,672
Inside the Professional allowance
Cost per matter
S$9.75
Platform + Pack, 400 matters
Payback
1.4 mo
On S$25,000 implementation

Recommended tier

Professional
Subscription
S$2,400 / mo
Included credits
250,000 / mo
Credits you would draw
167,200 / mo
Headroom
82,800 · ~198 more matters
Top-up required
None
Singapore Legal Practice Pack
S$1,500 / mo
Builder seats needed
4 of 15
Reviewer seats needed
31 of 100
Audit retention
Configurable
Total platform cost
S$3,900 / mo

67% of the monthly credit allowance consumed at this volume. Practice would not cover it, and would not give you configurable audit retention or SSO — which is why the recommendation is Professional rather than the cheaper tier the credit figure alone would suggest.

Cost per outcome vs your baseline

outcome unit = one matter reviewed
LineManual baselineWith KrewOSDelta
Reviewer minutes per matter6217−45
Reviewer cost per matterS$74.40S$20.40−S$54.00
Platform cost per matterS$0.00S$9.75+S$9.75
Fully loaded cost per matterS$74.40S$30.15−S$44.25
Monthly cost at 400 mattersS$29,760S$12,060−S$17,700
Reviewer hours displaced per month300300
Payback on S$25,000 implementation1.4 months

Displaced hours are reviewer minutes returned to fee-earning work, not headcount removed. The 17 minutes that remain are the professional sign-off on an evidenced draft — which stays, permanently, because that is the output your firm signs.

If you bring your own model keys

Comparison
LineManaged keysBYOK
Credits drawn per month167,20031,200
Platform cost per monthS$3,900S$3,900
Model inferenceIn creditsBilled by your provider
Matters before a top-up is needed~598~3,205
At 400 matters a month BYOK does not reduce your KrewOS invoice, because the credits sit inside your allowance either way. What it buys is five times the growth headroom and your own negotiated model rates. Past roughly 600 matters a month, it starts reducing the invoice directly.

Growth scenarios

managed keys
Matters / monthCreditsTop-upTotal platformCost / matter
20083,600S$3,900S$19.50
400 — your input167,200S$3,900S$9.75
600250,800S$8S$3,908S$6.51
1,000418,000S$1,512S$5,412S$5.41
1,000 with BYOK78,000S$3,900S$3.90
PDF

Email this business case

Send the full working — inputs, assumptions, per-node credit breakdown and the three-year view — as a PDF to yourself and your finance lead. We keep a copy so a solutions engineer can open the conversation with your numbers rather than ours.

Email the PDF
CHK

Check it against a real run

Every figure here derives from the published per-node credit table. Run the same template on three of your own documents during the trial and compare the ledger to this estimate before anyone signs anything.

Start free
TLK

Pressure-test the assumptions

Bring the estimate to a 45-minute session. The two numbers worth arguing about are your manual baseline and the residual review minutes — everything else is arithmetic on a published rate.

Book a demo
Book a demo

Bring your jurisdiction and your documents.

Forty-five minutes with a solutions engineer, run against your own material rather than a scripted sample. If your compliance lead can be in the room, bring them — the residency, retention and audit questions get answered on the call instead of in a questionnaire three weeks later.

Booking a demo never blocks the free trial. If you would rather touch it first, start free and book afterwards.

Tell us enough to make it useful

Reply within one business day
Work addresses only — we route by domain to avoid creating shadow workspaces inside one firm.
One or two sentences is plenty. It decides which Crew Template we set up before the call.

By submitting you agree to our privacy policy. We do not add you to a newsletter, and we do not pass your details to anyone outside wGrow.

What the 45 minutes covers

05
Your work, not our slides
Five minutes on the actual workflow and where it currently breaks
15
A governed run, end to end
A Crew Template configured to your jurisdiction, run live on a document you supply
10
The evidence panel and the approval task
What your reviewer actually sees — cited sources with authority and dates, failed gates, and what runs next after approval
08
Governance and residency
Abstention behaviour, effect declarations, audit export, where the data lives and what never leaves the region
07
Numbers and next step
Your estimator figures, the tier that fits, and an honest view of whether a pilot is the right shape

Who attends from our side

Solutions engineer
Always
Domain lead for your Pack
On request
Security or DPO counterpart
If you bring yours
Commercial lead
Second call, not this one
No slide deck and no sales engineer reading feature bullets. If we cannot show the governance working on your material, the call is not worth your time.

Bring, if you can

Two representative documents Your current process, in steps Monthly volume Minutes per item today Your compliance lead Any existing model contracts

Redacted documents are fine. Anything you send for a demo is processed in the Singapore region, is never used to train any model, and is deleted within 30 days unless you ask us to keep it for a pilot.

Would rather not book yet?

Watch a governed run
A recorded LawCrew replay with the evidence panel, no signup
Read the Trust Centre
Security, residency, PDPA, subprocessors, assurance
Request the security pack
DPA, SLA, pentest summary, CAIQ-lite behind a click-through NDA
Build the numbers first
Credits, cost per outcome, payback
Contact

Talk to someone who can answer procurement.

For deployment topology, customer-managed keys, negotiated DPAs, RFP responses, volume credit agreements and Pack licensing. If you need a demo rather than a contract conversation, book one here.

Send an enquiry

One business day

Direct lines

Sales and licensing
sales@krewos.ai
Procurement and RFP
procurement@krewos.ai
Security and disclosure
security@krewos.ai
Data protection officer
dpo@krewos.ai
Support, existing customers
support@krewos.ai
Press and analysts
press@krewos.ai
Partner programme
partners@krewos.ai

Registered entity

Legal name
wGrow Technologies Pte Ltd
Incorporated
Singapore, 2008
Registered address
Singapore
Primary data region
Singapore
Invoicing currencies
SGD, USD

Contracts are with wGrow Technologies Pte Ltd and governed by Singapore law unless separately negotiated.

Procurement pack

MSA and Terms of Service Data Processing Addendum Service Level Agreement Subprocessor list Penetration test summary Security whitepaper CAIQ / SIG-lite, pre-answered BCP and DR summary Insurance certificate Pack licence terms

Available behind a click-through NDA. Most of a security questionnaire is already answered in there — send it to your risk function before you send it to us.

Regional coverage

Singapore
Head office, delivery and solutions engineering
Direct
Malaysia
Direct, with certified implementation partners
Direct
Indonesia
Partner-led, aquaculture and agrifood focus
Partner
Hong Kong SAR and Australia
Served from Singapore, SGD or USD invoicing
Remote
KKrewOS Already have an account?Sign in
Account
Verify
Organisation
Invite team
First template

Check your inbox

Step 2 of 5

We sent a six-digit code to s.rajah@ridgewaypartners.com.sg. Enter it below. The code expires in 10 minutes.

A code, not a magic link. Corporate mail security in legal and financial firms pre-fetches links and silently consumes single-use tokens; a code survives that.
Did not arrive?
Resend available in 24 seconds · check spam and quarantine
Wrong address?
Go back and change it before verifying

What happens next

1
Account
Work email captured · password is set after verification, not before
Done
2
Verify email
Six-digit code, expires in 10 minutes
Now
3
Organisation and data region
Organisation name, then your data region — Singapore. The region is immutable for the workspace.
Next
4
Invite your team
Builders and reviewers. Reviewers land straight on an approval task — no workspace setup
Then
5
Pick your first Crew Template
Six production templates, or start from the Hub
Last

Your trial

no card
Credits
5,000 total
Duration
30 days
Seats
3 builder · 5 reviewer
Environment
Development only
Data region
Singapore
What you do not get on trial: no production deployment, no licensed Packs, no SSO. We would rather say it here than after you have set everything up.
Region is selected on the next step and cannot be changed afterwards. Read data residency before you choose.

KrewOS documentation

Everything you need to build, govern, operate and extend AI Agent Crews on KrewOS. If you have twenty minutes, start with the Quickstart — it ends with you reading a real evidence record and approving a real human task.

New to the vocabulary? Four levels, in order: an Agent does one job, a Pod is a team of Agents, a Crew Template is a reusable end-to-end workflow, and a KrewOS Pack is a licensed vertical bundle of templates, knowledge, policies and evaluations. The glossary has all of it.

Four paths

Pick the one that matches what you are trying to do today. They interlink heavily, so you will not be stuck in a lane.

Build

Assemble a crew from verified components without writing orchestration code, then take it to Git when you want to.

Govern

The mechanics that are enforced by the compiler and the runtime, outside the model prompt, where a prompt injection cannot reach them.

  • Evidence and abstention — sufficiency scores, declared evidence floors, and what a structured insufficiency result contains
  • Autonomy policies — the four stages, entry conditions, review rates and automatic reversion triggers
  • Release gates — evaluation thresholds that block promotion, and how to set one that is strict without being unshippable

Operate

Running crews in production, where things wait days for a human and must never fire the same external Action twice.

  • Runs and recovery — durable state, checkpoints, idempotency keys and compensation behaviour
  • The approval queue — task routing, SLAs, escalation and dual approval
  • Cost and outcomes — credits, budgets, Outcome Units and cost per outcome against your baseline

Extend

The engineering surface. Manifest-first, Git-native, and ejectable at any time.

  • CLIkrewos validate, krewos test, krewos package, krewos deploy
  • Custom Tools and Actions — the published extension contract and the sandbox rules
  • Exporting to Git — linked projects that round-trip through a reviewed diff, and ejected projects that are yours outright

Reference

The canonical technical artefacts. The Crew Manifest schema is published as a public contract — you can validate against it without an account.

  • Crew Manifest reference — every field, with a complete worked example
  • API reference — eleven domains, authentication, events, webhooks, errors, rate limits, OpenAPI download
  • CLI reference — install, authenticate, validate, test, package, deploy, inspect
  • SDK reference — language coverage and the component contract

Tutorials

Eight end-to-end guides, each one a job somebody actually has to do.

  1. Build a document review crew from the LawCrew template
  2. Create a Knowledge Pack from your own documents, with ACLs and freshness windows
  3. Configure BYOK and a model policy with a fallback chain
  4. Write an evaluation suite and set a release gate
  5. Add a governed Action through n8n with an idempotency key
  6. Expose your crew as an MCP tool to an external assistant
  7. Export to Git and extend with a custom Tool
  8. Graduate a crew from full review to supervised sampling

Conventions in these docs

Vocabulary is shared with the product and the glossary renders from the same source, so a term on this page means exactly what it means on the screen you will see later.

  • Tools read or compute. Actions cause external side effects. The distinction is load-bearing and we never blur it.
  • Knowledge is not Memory. Knowledge is source-backed organisational content retrieved at run time; Memory is task state.
  • Runtime capitalised means the KrewOS Runtime surface; lower-case "execution" is the generic sense.
  • British spelling throughout — organisation, licence as a noun, catalogue, programme.
Docs are versioned against the platform release. Anything marked Preview can change without a breaking-change notice; anything not marked is covered by the deprecation policy in the changelog.

Getting help

Search covers docs, the glossary, the Manifest schema and the changelog together. If the answer is not there, the support address on your plan is in the workspace footer, and security questions go to security@krewos.ai regardless of plan.

Quickstart

Target: a governed run finished, evidenced, approved and audited in under twenty minutes. We use the Content Studio Crew Template because it is the lowest-risk template, needs no connectors and runs on a sample corpus we ship with it. Everything you learn here applies unchanged to LawCrew, Finance Close and AquaMind.

You will spend roughly 90 credits. Your trial has 5,000, so this costs about 1.8% of it. Credit consumption is shown at every step because surprise billing is the fastest way to lose a technical evaluator.

1. Prerequisites

  • A KrewOS account — start free, no card, 5,000 credits
  • Node 20 or later, or any environment that can run a single static binary
  • About twenty minutes and a terminal

You do not need model provider keys. The trial routes inference through KrewOS-managed keys. If you want to use your own from the start, skip ahead to configuring BYOK and come back.

2. Install and authenticate the CLI

# install
npm install -g @krewos/cli

# authenticate against your workspace — opens a browser, stores a scoped token
krewos auth login --region sg
✓ Signed in as s.rajah@ridgewaypartners.com.sg
✓ Tenant  ridgeway-partners        Region  sg-central-1
✓ Wallet  5,000 credits            Expires in 30 days

The CLI and the Studio are two views of the same manifest. Anything you do here shows up in the browser immediately, and vice versa.

3. Create a project from a Crew Template

Template-first is the default. A blank canvas is available but de-emphasised, because starting from something that already passes an evaluation suite is faster than starting from nothing.

# list the templates available to your tenant
krewos template list
  content-studio        Content Studio            v4.2.0   risk: low
  lawcrew-doc-review    LawCrew Document Review   v3.0.2   risk: high · pack required
  finance-close         Finance Close             v2.4.1   risk: high · pack required
  aquamind-advisory     AquaMind Advisory         v2.7.1   risk: medium · pack required
  bizdev-intel          BizDev Intelligence       v1.9.4   risk: low
  ecom-selection        eCommerce Selection       v1.3.0   risk: low

# scaffold a project in the development environment
krewos project create quickstart \
  --template content-studio \
  --language en,zh-Hans \
  --jurisdiction SG \
  --env development
✓ Project quickstart created
✓ Manifest written to ./quickstart/crew.manifest.yaml
✓ 1 Crew · 3 Pods · 9 Agents · 2 human wait states · 1 declared Action

What just got written

The manifest is the source of truth. The canvas is an editor over it, plain-English changes compile into it, and Git commits resolve to it.

krewos manifest show --summary
  crew: content-studio
  evidence_floor: 0.72          # abstain below this sufficiency score
  autonomy: full_review          # every crew starts here, always
  effects:
    - kind: publish_cms
      idempotency: required
      approval: senior_editor    # gate proven at compile time
  knowledge:
    - pack: sample-corpus-en     # shipped with the template

4. Attach your own knowledge (optional)

The sample corpus is enough to finish this guide. If you would rather see retrieval over your own material, build a Knowledge Pack now — it takes about two minutes for a small folder.

krewos knowledge create house-style \
  --from ./docs \
  --acl workspace \
  --freshness 180d
✓ Indexed 34 documents · 1,182 chunks · 41 credits
# attach it to the crew and re-resolve the manifest
krewos project attach-knowledge house-style
Freshness windows matter. When a source expires or materially changes, every artefact that relied on it is identified and its owners notified. A Knowledge Pack with no freshness window will not raise that signal.

5. Validate and test before you run

Validation is static. It proves properties about the crew rather than testing them — including that no path runs from untrusted input to an external side effect without an intervening approval gate.

krewos validate
✓ Typed ports          all 14 connections resolve
✓ No orphan nodes      0 found
✓ Bounded loops        revision loop capped at 3 iterations
✓ Effect declarations  1 declared, 1 gated
✓ Taint analysis       no untrusted input reaches publish_cms without approval
✓ Permissions          no node holds more scope than it declares
✓ Manifest valid       ready to test

krewos test --sample
✓ 6 sample cases · 6 passed · evidence floor respected on all
  cost: 34 credits (platform 12 · model 22)

If validation fails, there is no release to deploy. That is the point — the compiler is a gate, not a linter.

6. Run a real case

krewos run start \
  --input ./samples/brief-sustainable-aquafeed.json \
  --watch
✓ RUN-9C41A8 admitted · reserved 260 credits
  [00:04] Research Pod          7 retrievals · sufficiency 0.86
  [00:31] Outline               accepted
  [01:12] Drafting              2,140 words · 11 citations
  [01:58] Compliance gate       passed · 0 flags
  [02:10] Revision loop         1 of 3 · readability
  [02:44] Senior editor gate   waiting for a human
  run parked at CP-6 · this is a normal state, not a timeout

The run is now durable. It will survive a worker restart, a deploy and a rollback, and it will wait days for the approval without consuming anything but a few credits of task management.

7. Read the evidence behind a claim

This is the step that matters. Open the run in Studio, or inspect it from the terminal.

krewos run evidence RUN-9C41A8 --claim c-07
  claim      "Feed conversion ratios below 1.2 are achievable in
              recirculating systems with stable dissolved oxygen."
  sufficiency 0.86   floor 0.72 · above floor, no abstention
  sources
    [1] SFA Aquaculture Advisory 2024/03   authority: regulator · dated 2024-08-14
    [2] Tan & Loh, Aquaculture Research     authority: peer-reviewed · dated 2023-11-02
    [3] Internal trial log, Pulau Ubin site authority: first-party · dated 2025-02-19
  conflicts  none
  staleness  source [2] expires in 214 days
Try forcing an abstention: run the same crew with the knowledge pack detached. The crew will not guess. It returns a structured insufficiency result naming what it could not establish and which sources would resolve it, and the case routes to the knowledge-gap queue rather than the failure log.

8. Approve the human task

Approvals are durable workflow states, not emails. The reviewer sees the business purpose, the requested decision, the risk classification, the diff, the cited sources with authority and dates, any failed or marginal gates, and what runs next after approval.

krewos task list --mine
  TASK-4471  Senior editor gate  RUN-9C41A8  waiting 6m  risk: low

krewos task approve TASK-4471 --note "Citations check out, publish."
✓ Correction Record CR-1182 written · reviewer s.rajah · immutable
✓ Action publish_cms fired with idempotency key run-9C41A8-cp7
✓ RUN-9C41A8 complete

9. Read the audit trail and the credits

krewos run audit RUN-9C41A8 --format json > audit.json
✓ 41 trace records · 9 nodes · 14 model calls · 7 retrievals · 1 human decision

krewos run cost RUN-9C41A8
  platform     52 credits    S$0.52
  model        38 credits    S$0.38
  reserved    260            released 170 at close
  settled      90 credits    S$0.90
  outcome unit  1 article published
  cost/outcome  S$0.90

The audit export contains the run, the release, every component version, the model profiles, the evidence with provenance, the human decision with identity and timestamp, the policy outcomes and the cost records. It is the artefact you hand an auditor.

Where to go next

Glossary

The vocabulary, defined once.

The published glossary renders from the same source as the product, so a term on this page means exactly what it means on the screen you will see later. Every term has its own page.

HierarchyGovernanceEvidence RuntimeCatalogueEngineering Commercial26 terms
The four levels
Agent

The smallest unit of work in KrewOS. One Agent has one job, a typed input and output contract, a declared model profile, an explicit set of Tools it may call and an explicit set of effects it may cause. Agents do not decide their own scope.

krewos.ai/glossary/agent
Pod

A coordinated team of Agents that produces one composite result — for example an Evidence Research Pod of four Agents running eleven retrievals and reconciling them. Pods nest, collapse in the canvas, and carry their own typed contract to the rest of the crew.

krewos.ai/glossary/pod
Crew

A deployed, running instance of a Crew Template inside one Project and Environment, bound to a specific immutable Release. "The crew" is what your operators talk about; the template is what your builders edit.

krewos.ai/glossary/crew
Crew Template

A reusable, versioned, end-to-end workflow — Agents, Pods, routing, human wait states, declared effects, evidence floor and evaluation suite — designed to be configured rather than rebuilt. Six ship as production templates; more come with Packs.

krewos.ai/glossary/crew-template
KrewOS Pack

A licensed vertical package: Crew Templates, Knowledge Packs, deterministic policy packs, evaluation datasets and dashboards for one industry and jurisdiction, maintained and dated by its publisher. Licensed annually and separately from the platform.

krewos.ai/glossary/krewos-pack
Crew Manifest

The canonical, versioned, machine-readable definition of a crew. The visual canvas is an editor over the manifest, plain-English changes compile into it, and Git commits resolve to it. It can be validated, diffed, exported, tested and deployed. The schema is published as a public contract.

krewos.ai/glossary/crew-manifest
Evidence and abstention
Evidence

The set of retrieved sources supporting a specific claim, each carried with its authority tier, its date and its retrieval context. Evidence travels with the output all the way to the reviewer and into the audit export — it is not a debug artefact.

krewos.ai/glossary/evidence
Sufficiency Score

A score assigned to an evidence set against the specific claim it is asked to support, combining source authority, recency, coverage and agreement. It is compared against the crew's declared evidence floor at run time to decide whether to answer or abstain.

krewos.ai/glossary/sufficiency-score
Evidence floor

The minimum sufficiency score a Crew Template declares for its claims. Below the floor the crew must not answer. The floor is a manifest property, versioned and diffable, not a prompt instruction — so it cannot be argued away by the input.

krewos.ai/glossary/evidence-floor
Abstention

The structured result returned when retrieved evidence falls below the declared floor. It names what could not be established and which sources would resolve it, and routes to a human knowledge-gap queue. Abstentions are reported separately from failures, because a missing source is not a broken crew.

krewos.ai/glossary/abstention
RAG

Retrieval-augmented generation: grounding model output in retrieved source content rather than parametric recall. In KrewOS, retrieval is always attributable — every retrieved chunk keeps its source, authority and date so the claim it supports can be traced.

krewos.ai/glossary/rag
Knowledge Pack

A governed collection of source documents indexed for retrieval, with access control lists, freshness windows and dated currency assertions. Knowledge is not Memory: Knowledge is source-backed organisational content; Memory is task state across a run.

krewos.ai/glossary/knowledge-pack
Control, effects and autonomy
Action

A step that causes an externally visible side effect — sending, filing, posting, paying, publishing. Every Action requires an idempotency key and a declared compensation behaviour, and may require human approval. Distinct from a Tool, which only reads or computes.

krewos.ai/glossary/action
Effect Declaration

The statement each component makes about what it reads, writes, spends and causes externally. The compiler statically proves those properties before a Release exists — including that no path runs from untrusted input to an external side effect without an intervening approval gate. If the property does not hold, there is no release to deploy.

krewos.ai/glossary/effect-declaration
Progressive Autonomy

The mechanism by which a crew earns a lower review rate against measured accuracy at a published confidence bound, and loses it automatically on breach. Four stages: full review, supervised sampling, extended sampling, and a regulated floor that never graduates.

krewos.ai/glossary/progressive-autonomy
Review Sampling

Risk-weighted selection of outputs for human review once a crew has graduated past full review. Never uniform — high-risk, high-value and low-confidence outputs are sampled far more heavily. Reviewer behaviour is itself measured, because a sampling regime is only as sound as the reviews calibrating it.

krewos.ai/glossary/review-sampling
Correction Record

The immutable record of a human approval, rejection or edit, tied to a named reviewer, a run, a release and a component version. Append-only: corrections supersede, they never rewrite. Expert-confirmed corrections are promoted into the crew's evaluation suite, which is why the suite compounds.

krewos.ai/glossary/correction-record
Evaluation Suite

The versioned set of cases and scorers a crew must pass before a Release can be promoted. Suites start from the Pack's datasets and grow out of real disputed cases from your own work, which is why a competitor cannot copy yours.

krewos.ai/glossary/evaluation-suite
Platform and deployment
Control Plane

The central layer holding identity, the catalogue, manifests, policies, evaluations, releases and audit. It stays under one governance model regardless of where execution happens. Availability is committed at 99.9% monthly where the contract carries the commitment, and a month below it is credited automatically.

krewos.ai/glossary/control-plane
Execution Plane

The layer that runs the compiled plan and holds run state. It can sit in KrewOS Cloud, a dedicated environment, your own VPC, a hybrid topology or your own infrastructure. Splitting the planes is what lets you keep one governance model and still satisfy residency.

krewos.ai/glossary/execution-plane
BYOK

Bring your own key. Register your model provider credentials as encrypted secret references so inference runs against your account at your negotiated rates and your provider bills you directly. Platform credits are unchanged; the model meter reads zero. Keys never appear in prompts, logs, manifests, exports or support tools.

krewos.ai/glossary/byok
MCP

Model Context Protocol. KrewOS speaks it in both directions: deployed crews are callable as standard tools by external assistants with policy, evidence and approval enforced by the runtime rather than the caller, and approved external MCP servers are consumable as Tools under the same registry, permission and audit controls.

krewos.ai/glossary/mcp
Linked Project

A project exported to Git that continues to round-trip with the platform. Changes made in the repository return through a reviewed diff and an approval workflow before they touch a manifest, so the engineering workflow does not bypass governance.

krewos.ai/glossary/linked-project
Ejected Project

A project exported to Git and detached permanently. The repository — manifest, components, schemas, prompts, policies, evaluations, tests, deployment files — is yours outright, and the runtime APIs still work. Eject rights exist so the lock-in question has a real answer.

krewos.ai/glossary/ejected-project
Vibe Coding

Describing an intended change in plain English and letting the platform produce a change plan, a visual diff, a validation result and a test run for you to accept, amend or reject. It never edits production directly. Buyer-facing pages say "describe the change in plain English"; engineers call it Vibe Mode.

krewos.ai/glossary/vibe-coding
Assurance and commercial
Golden Crew

An internal reference crew held at a known-good state and used to validate platform releases before they reach tenants. It is a validation instrument, not a customer-facing concept — on customer surfaces the equivalent idea is simply a reference crew.

krewos.ai/glossary/golden-crew
Maintained Pack

A KrewOS Pack whose publisher commits to a stated update cadence, dated currency assertions on its knowledge, and change notifications to entitled tenants when a source materially changes. The alternative is a Pack that was accurate on the day it was written.

krewos.ai/glossary/maintained-pack
Outcome Unit

The unit of business outcome a crew declares — a matter reviewed, a reconciliation closed, an article published, an advisory issued. Cost per outcome and human minutes displaced are reported against it, from the same records that enforce your budgets.

krewos.ai/glossary/outcome-unit
Credit

One unit of metered platform consumption, prepaid and drawn down as crews run. One credit is one Singapore cent. Two meters draw on one wallet: platform credits, always charged, and model credits, which read zero under BYOK.

krewos.ai/glossary/credit
Availability service credit

The remedy owed when a month falls below a committed availability figure. Despite the name it is money against your next invoice, not platform credits: it creates no lot, never expires, and is paid out in cash if you leave before it is used up. Issued automatically from the published attainment, on the published schedule.

krewos.ai/glossary/availability-service-credit

Terms we will not use

"Fully autonomous", "AI employee", "no hallucinations", "MAS certified", "PDPA compliant" as a property of software. Each is either unsupportable or contradicts a mechanic the product actually enforces. We say abstains rather than speculates, PDPA-aligned, and aligned with named MAS guidance.

Terms we are careful with

KrewOS Hub is a catalogue, not a marketplace. A prepaid purchase of credits is a bundle or top-up, never a "credit pack" — Pack is a reserved product object. Tools read; Actions cause effects; the two are never collapsed into "integrations".

Where the vocabulary comes from

One source, rendered into the product UI, the documentation and this page together. Vocabulary drift between a marketing page and the screen a user later sees is one of the cheapest trust signals to get right and one of the most common to get wrong.

Changelog

Every release, dated and tagged.

Regulated buyers read changelogs to judge whether a vendor is disciplined. Breaking changes are flagged, deprecations carry a stated window, and security fixes are published even when they are dull.

Current release
v1.2.4
Cadence
Fortnightly, Thursdays SGT
Deprecation window
Two minor versions, min 90 days
Breaking changes, last 12 mo
2
In-flight runs
Continue on their own release
AllStudioHubRuntime GovernancePacksSecurityAPI & CLI

v1.2.4 · 14 August 2026

Stableno breaking changes
Runtime New Credit reservation and per-checkpoint settlement
Runs now reserve the crew's recent P90 run cost plus a variance buffer at admission and settle at each checkpoint. A run that exhausts the wallet parks in awaiting_credit for 72 hours and auto-resumes on top-up rather than failing. Side-effect Actions are withheld while a wallet is short.
Governance New Reviewer calibration metrics
Sampling regimes now report reviewer agreement, median decision time and override rate per reviewer. Autonomy graduation is blocked when reviewer agreement falls below the configured bound.
Studio Improved Diff-before-apply for plain-English changes
Change plans now show the manifest diff, the validation result and the sample test run on one screen, with per-hunk accept. Previously accept was all-or-nothing.
Packs Improved Singapore Legal Practice Pack v4.1
Clause library refreshed to 31 July 2026 currency. Twelve new evaluation cases drawn from disputed tenancy matters. Change notice sent to entitled tenants.
API & CLI Fixed krewos run audit pagination
Exports over 10,000 trace records truncated silently at the page boundary. Records were never lost, but the export was incomplete. Affected exports can be regenerated.
Security Fixed Secret reference redaction in support tooling
A support view could render the last four characters of a tenant-managed secret reference identifier. No key material was ever exposed. Reported through the disclosure programme, fixed within 48 hours.

v1.2.3 · 31 July 2026

Breakingmigration required
Breaking change. Effect Declarations now require an explicit compensation block on every Action. Manifests without one fail validation. Announced 5 May 2026, 87 days of notice. Run krewos manifest migrate --to 1.2.3 to add scaffolded declarations for review.
Governance Breaking Mandatory compensation behaviour on Actions
Every declared external effect must state what happens if it needs to be undone. Undoable actions declare compensation: none explicitly, which is a decision rather than an omission.
Runtime New Canary releases
Route a configurable share of production traffic to a candidate release with automatic reversion on evaluation-gate breach. Professional and above.
Hub Improved Private tenant catalogues
Publish verified components to your own organisation without publishing to the world. Lineage and verification tier are tracked identically.
Runtime Deprecated runs.list v1 endpoint
Superseded by runs.search with cursor pagination. Removal no earlier than v1.4.0 or 30 November 2026, whichever is later.

v1.2.2 · 17 July 2026

Stable
Governance New Staleness propagation
When a source expires or materially changes, every artefact that relied on it is identified and its owners notified, with the affected claims listed. Previously staleness was visible only on the Knowledge Pack itself.
Governance New Conflict carry-forward
Where sources of comparable authority disagree, both positions are carried into the evidence record and surfaced to the reviewer. The system no longer silently prefers the higher-ranked retrieval.
Packs New Aquaculture Operations Pack v2.0
Adds barramundi and grouper knowledge packs, revised dissolved-oxygen safety rules, and 40 evaluation cases built from real incident reports.
API & CLI Improved krewos validate taint analysis output
Failures now print the full path from untrusted input to the ungated effect, rather than naming only the offending node.

v1.2.1 · 3 July 2026

Stablesecurity
Security Fixed Dependency advisories in the sandbox image
Three moderate advisories in the code-execution sandbox base image. No exploitation observed. Patched image rolled to all regions within the maintenance window.
Runtime Fixed Duplicate task notification on escalation
Escalating an approval task could notify the original assignee twice. The Correction Record and the audit trail were always correct; only the notification duplicated.
Studio Improved Cost estimate on the canvas
Per-node credit estimates now split platform and model meters, and respect a BYOK configuration when one is attached.

v1.2.0 · 19 June 2026

Major
Governance New Progressive autonomy, generally available
Four-stage graduation with risk-weighted sampling, published confidence bounds and automatic reversion on breach. Regulated crews can be pinned to the permanent full-review floor.
Runtime New Compile-time proof of gated effects
The validator now proves statically that no path runs from untrusted input to an external side effect without an intervening approval gate. If the property does not hold, no release is produced.
Hub New Verification tiers
Draft, Tested, wGrow verified, Tenant verified and Deprecated, each with published criteria. Compatible updates may be recommended but are never installed silently.
API & CLI New MCP server and client
Deployed crews are callable as MCP tools with policy and approval enforced by the runtime. Approved external MCP servers are consumable as Tools, with per-tool admission control.

How we version

Breaking changes

Announced at least 90 days ahead, flagged in the changelog and by email to workspace administrators, with a migration command where one is possible.

Deprecations

Supported for at least two minor versions or 90 days, whichever is longer. Removal dates are published when the deprecation is announced, not later.

In-flight runs

A long-running case continues on the release it started on, even after you deploy or roll back. Releases are immutable and dependency-locked, so nothing changes underneath a matter that is already open.

Case studies

Two crews, measured over a year.

Both studies include the numbers, the controls and the part that did not work. A case study with no friction in it reads as marketing, and converts like marketing.

LawCrew document review at Ridgeway & Partners

A 41-lawyer Singapore commercial practice, reviewing commercial tenancy and services agreements under Singapore law. Regulated output, permanent full human review, and a managing partner who had already rejected two AI tools.

Matters / month
412
Up from 240 with the same team
Reviewer minutes / matter
19
From 64 · −70%
Cost per matter reviewed
S$9.46
Platform and Pack, fully loaded
Evaluation pass rate
96.8%
From 88.1% at go-live

The situation

First-pass review of incoming commercial agreements was handled by four paralegals and a supervising associate. Average 64 minutes per agreement, a two-day queue in busy months, and no consistent record of which sources a reviewer had relied on. The firm had trialled two general-purpose AI tools and stopped both — not because the drafting was poor, but because nobody could answer the question a client eventually asks: on what basis did you conclude that?

The partner's condition for a third attempt was explicit. Every clause-level conclusion had to be traceable to a source with a date, and a named person had to appear against every output that left the firm.

The crew

LawCrew Document Review from the Singapore Legal Practice Pack, configured to Singapore governing law with the firm's own precedent library attached as a Knowledge Pack.

Jurisdiction routerEvidence Research Pod · 4 Agents DraftingAdversarial Reviewer Regulatory Review Pod · deterministic gatesProfessional approval
The controls
  • Evidence floor set at 0.78, higher than the Pack default of 0.72, at the firm's insistence.
  • Autonomy pinned to the regulated floor — 100% human review, permanently. No graduation path enabled.
  • Dual approval on any matter classified high-risk by the Regulatory Review Pod.
  • Per-matter access control; no client data leaves the Singapore region; nothing is used to train any model.
  • Audit retention configured at seven years to match the firm's own file retention policy.

Twelve-month trajectory

Evaluation pass rate, monthly
Go-live pass rate
88.1%
Month 12 pass rate
96.8%
Evaluation cases at go-live
60, from the Pack
Evaluation cases at month 12
247
Of those, from Correction Records
187
Abstention rate
4.1%
Review rate
100%, by design

Commercials

Tier
Professional
Subscription
S$2,400 / mo
SG Legal Practice Pack
S$1,500 / mo
Credits drawn, BYOK
34,700 / mo
Top-ups purchased
None
Reviewer seats in use
38 of 100
Payback on implementation
1.6 months

What did not work

Honest bit

The first eight weeks were worse than the manual process. The firm's precedent library had been maintained as a shared drive with no dates on anything, so the Evidence Research Pod could not establish currency and abstained on roughly one matter in five. Reviewers read that as the tool failing.

It was not. It was the tool refusing to guess about which version of a clause was current — which, once the library was dated and re-indexed, turned out to have been the correct behaviour on every single one of those matters. The firm now treats the abstention rate as a knowledge-quality metric rather than a product defect, but that reframing took a difficult month and two sessions with the supervising associate.

"I did not buy a drafting tool. I bought the ability to sit in front of a client, or the Law Society, and show them exactly which authorities a conclusion rested on and which of my people signed it. That is what makes it usable in a practice. The speed is a bonus."

Sarah Rajah · Managing Partner, Ridgeway & Partners LLP · Singapore

AquaMind advisory at Selat Aquafarms

A barramundi and grouper operation across nine sea-cage sites in the Johor Strait, with 14 farm technicians and one aquaculture specialist covering all of them.

Advisories / month
1,340
From 210 specialist-answered
Median response time
2.4 min
From 5.8 hours
Cost per advisory
S$1.94
Platform and Pack, fully loaded
Abstention rate
11.3%
Escalated to the specialist

The situation

A technician who sees a dissolved-oxygen reading drop at 5am needs an answer before the shift supervisor wakes up. The single specialist could answer roughly 210 questions a month within a working day; everything else was resolved by whoever had the most experience on site, which is how a confident wrong answer about water chemistry kills a pond.

The operation is not regulated in the way a law firm is, but the failure mode is more expensive and much faster. The design brief was the inverse of Ridgeway's: speed first, but with a hard rule that the system must say when it does not know.

The crew

AquaMind Advisory from the Aquaculture Operations Pack, with the farm's telemetry feeds connected as read-only Tools and species knowledge packs for barramundi and grouper.

Dynamic routerExpert advisory panel · 5 Agents Evidence verificationSafety gate · deterministic Telemetry cross-checkTechnical sign-off on escalation
The controls
  • Evidence floor at 0.70, with a hard deterministic safety gate on anything touching dissolved oxygen, salinity, medication or harvest timing.
  • Autonomy graduated from full review to extended sampling at 12% over seven months, on measured accuracy, with automatic reversion armed.
  • Every abstention escalates to the specialist with the reading that would resolve it named explicitly.
  • Bilingual output in English and Simplified Chinese; mobile approval; durable runs to survive intermittent connectivity on the water.

Autonomy graduation

StageReview rateAccuracy
Months 1–3 · full review100%91.2%
Months 4–5 · supervised sampling25%95.6%
Months 6–7 · reverted on breach100%89.4%
Months 8–12 · extended sampling12%97.3%

The month-six reversion was automatic and correct: a feed-supplier document set had been replaced without notice and accuracy fell below the bound within four days. Nobody had to notice it.

Commercials

Tier
Professional
Subscription
S$2,400 / mo
Aquaculture Operations Pack
S$1,000 / mo
Credits drawn, managed keys
218,400 / mo
Top-ups purchased
None · 87% of allowance
Specialist hours returned
63 / month
Ponds lost to chemistry events
0, from 2 the prior year

What did not work

Honest bit

Adoption stalled at three of nine sites for four months. The crew was answering well; the technicians at those sites simply did not trust an answer that arrived on a phone. What changed it was not training — it was showing them the abstentions. Once technicians saw the system decline a question about a medication interaction and name the water test that would settle it, they started using it for everything.

The lesson we did not expect: the abstentions built more trust than the correct answers did. We now put the abstention log in front of new sites during onboarding, before any of the success metrics.

"The morning it told my technician it could not answer and asked him to run an ammonia test first, I stopped worrying about it. Anything that will admit it does not know at five in the morning is something I can put in front of my crew."

Lim Wei Sheng · Operations Director, Selat Aquafarms Sdn Bhd · Johor

How we publish these

Every figure comes from the tenant's own Cost & Outcomes records and evaluation history, not from a survey. Both customers reviewed and approved their numbers before publication, and both agreed to include the section that did not go well. We do not publish a case study without measured outcomes and at least one piece of friction.

Run the same arithmetic on your volume

Both of these started as an estimator output and a 45-minute session. Put your own volume and your own manual baseline in, and bring the result to the call.

Open the estimator Book a demo
Company

Built by a company that will still be here in five years.

KrewOS is made by wGrow Technologies Pte Ltd, a Singapore software and delivery firm founded in 2008. We have shipped systems into regulated Southeast Asian businesses for eighteen years, and we built this platform because we needed it ourselves.

Founded
2008, Singapore
Clients served
300+
Ownership
Private, founder-led
Funding
Self-funded, profitable
Crews in production
6, on our own work

Why we built it

wGrow is a services company. That is the whole explanation, and it is worth saying plainly rather than dressing it up as a founding vision.

01

We hit the wall ourselves

By 2024 we were running multi-agent systems for our own content, business development and eCommerce work. They worked. What we could not do was hand one to a client in a licensed industry, because we had no way to prove what any output had been based on or who had approved it.

02

Governance was 80% of the build

Every client engagement rebuilt the same scaffolding: evidence models, approval workbenches, evaluation harnesses, idempotency, cost attribution, audit export. Roughly eighteen months of work, re-done per client, none of it the thing the client was paying for.

03

So we made it the product

KrewOS ships the governance as enforced product mechanics and the domain expertise as licensed Packs. The six crews on the platform are not demonstrations — they are wGrow's own production systems, rebuilt on it.

"We are not a research lab and we are not trying to be. We are a delivery company that got tired of rebuilding the same audit trail for the fourteenth time, and decided the audit trail was the product."

wGrow Technologies · founding note, 2025

What durability actually looks like

Regulated buyers are right to ask whether a vendor will still exist when the contract renews. Here is what we can show rather than assert.

The record

Years in operation18
Clients served since 2008300+
Consecutive profitable years11
External capital raisedNone
Primary marketsSingapore, Malaysia, Indonesia
Delivery and engineering staffSingapore-based
Contracting entitywGrow Technologies Pte Ltd

What we deliberately do not do

We do not run an unrestricted marketplace
Every published component is reviewed and carries a verification tier. The Hub is a catalogue.
We do not build self-modifying production crews
Changes go through a diff, a validation pass and a release. Always.
We do not replace your ERP, CRM, warehouse or n8n
We call them, under declared effects and approval gates.
We do not train foundation models
We govern access to approved ones. No customer data is used to train any model, ours or a provider's.
We do not raise venture capital to buy growth
An IR page would signal fundraising, and regulated buyers read fundraising as instability.

How we work

Singapore first

Built for ASEAN regulated work rather than adapted to it. Default data region Singapore, British spelling, SGD pricing, and jurisdictional Packs written by practitioners who work here.

Say the unflattering thing

We publish what the platform does not do, when not to use it, our real certification status, and the parts of customer deployments that went badly. It is a better filter than a feature list.

Vocabulary discipline

One glossary renders into the product, the docs and the marketing site. A term means the same thing on a pricing page and on the screen you see six months later.

No lock-in theatre

Export a complete engineering repository at any time. Ejected projects are yours outright and the runtime APIs still work. The Crew Manifest schema is published as a public contract.

Leadership

Founder-led since 2008, with the engineering, delivery and domain leads for each Pack named in the procurement pack. We do not publish photographs of a leadership team on a marketing page; we put the actual names in front of the people signing the contract.

Working here

We hire in Singapore for platform engineering, evaluation and domain research, and we hire practitioners — lawyers, controllers, aquaculture technicians — to write and maintain the Packs. Open roles are listed on the careers page.

Talk to us

Sales
sales@krewos.ai
Security
security@krewos.ai
Press
press@krewos.ai
Contact
KKrewOS Account and system statesSign upSign in

Account and system states

Every state a signed-out or blocked user can land in, on one page. Each is a centred single-card layout in production; they are shown together here so the copy can be reviewed as a set.

Verification email sent

/verify

We sent a six-digit code to s.rajah@ridgewaypartners.com.sg. It expires in 10 minutes.

Nothing arrived? Resend in 24 seconds, or check whether your mail gateway has quarantined it. We use a code rather than a link because corporate mail security pre-fetches links and consumes single-use tokens.

Reset your password

/reset

Enter your work email and we will send a reset code. If your organisation uses SSO you will be sent to your identity provider instead — we will not create a second credential alongside it.

For your security we return the same confirmation whether or not the address is registered.

You have been invited

/invite/<token>

Sarah Rajah has invited you to Ridgeway & Partners on KrewOS as a Reviewer.

Organisation
Ridgeway & Partners LLP
Seat class
Reviewer
You will see
Approval Workbench, your own runs
Data region
Singapore
Invitation expires
In 6 days
Decline

Accepting takes you straight to the approval task waiting for you. There is no workspace to create and no template to choose.

Trial expired

Read-only

Your 30-day trial of Ridgeway & Partners ended on 14 August 2026. The workspace is now read-only. Nothing has been deleted.

Crews built
2
Runs completed
37
Credits used
3,914 of 5,000
Manifests, knowledge and runs
Retained 30 days
Export
Available now
Estimate my usage Export everything
After 30 days the workspace is deleted on the published retention schedule. You will get a notice at 14 days and again at 3 days. Nothing is deleted silently.

Credits exhausted

4 runs parked

Your wallet reached zero at 09:41 SGT. Four runs are parked at their last checkpoint in awaiting_credit. No run has been cancelled and no external Action has fired since the wallet ran short.

RunParked atGrace remaining
RUN-9C4471CP-4 · adversarial review71h 12m
RUN-9C4468CP-2 · evidence research71h 08m
RUN-9C4462CP-6 · awaiting editor70h 55m
RUN-9C4459CP-3 · drafting70h 41m
How credits work
Parked runs resume automatically from their checkpoint the moment credits land, in submission order. Idempotency keys guarantee no Action fires twice. After 72 hours they move to suspended, and can still be resumed once funded.

Page not found

404

That page does not exist, or it moved when the documentation was restructured. Nothing is wrong with your account.

Documentation
Build, govern, operate, extend
Glossary
Every term, one page each
Pricing
Tiers, credits, Packs
Trust Centre
Security, residency, privacy, assurance

Scheduled maintenance

In progressstatus.krewos.ai

The Control Plane is undergoing planned maintenance from 02:00 to 04:00 SGT, 16 August 2026. Studio, the Hub and administration are unavailable. Announced 14 days ago to all workspace administrators.

Control Plane
Maintenance
Studio, Hub, admin unavailable
Execution Plane · SG
Operational
Runs continue and settle normally
Model Gateway
Operational
All approved providers
Approvals
Operational
Reviewers can approve as normal
In-flight runs are unaffected. Durable state means a run waiting on a human, or mid-Pod, simply continues — maintenance on the Control Plane does not stop execution. Status is hosted on separate infrastructure from the platform, deliberately, so it does not go down with the thing it reports on.

Operating KrewOS · Saturday 15 August

Everything across the customer base that needs a human today, ranked by what it costs if nobody touches it. Production estate · 38 tenants · 1 credit = S$0.01.

INC-0231 · Elevated latency, Anthropic Singapore endpoint · Sev 2 · opened 09:41 · 6 tenants affected · P95 4.8s against a 1.9s baseline · customer statement published 10:02 · Open incident
Tenants active
34
27 paid · 7 trial · 1 lead in provisioning
Credits sold MTD
4,180,000
S$38,240 cash received · avg S$0.00915/credit
COGS MTD
S$18,210
Model 84% · variance to provider invoices −S$142 (0.8%)
Gross margin MTD
61.4%
Revenue S$47,180 · +2.1pt vs July · −4.1pt if rate card v5 slips
Under 14 days runway
3
Tanjong Aqua 2d · Harbourfront 4d · Sentosa 11d
Open incidents
2
INC-0231 Sev 2 · INC-0232 Sev 3 · 9 tenants affected in total
Awaiting a second pair of eyes
9
Oldest 4d · S$25,498.80 of value at risk

Attention queue

Ranked by consequence, not recencyDirectory
CRD
Straits Content Co · 120,000 credits granted before capture
Auto-topup fired on INV-2026-0431 (S$1,124.88) at 10:04 today under the credit-risk election, after the card declined twice on 13 Aug. Balance now 162,180 credits against an invoice not yet captured.
Capture pendingOpen credits
INV
Harbourfront Legal · INV-2026-0418 overdue 41 days
S$18,400 outstanding on Net 14 terms. The dunning ladder reaches automatic suspension in 4 days; enterprise holds must be released by hand.
S$18,400Open dunning
DUE
Harbourfront Legal · credits and the suspend gate both land on 19 Aug
12,400 credits against 2,937/day is 4 days, and S$18,400 has been overdue 41 days. Auto-topup was disabled at D14 so the balance will not refill, and the D45 suspend gate falls the same day the credits run out.
Both 19 AugOpen lifecycle
TOP
Bukit Timah Accountancy · auto-topup disabled after 3 failed charges
Corporate card •••• 2298 expired 07/26. Retries at +1h, +6h and +24h all declined. 18 days of runway remain, so this is a call, not a crisis — yet.
Card expiredOpen billing
APR
Refund request · Ridgeway Legal LLP · S$1,240
Raised 7h ago by k.ong against INC-0224 duplicate dispatch. Above the S$500 desk limit, so it needs a second approver who is not k.ong. Request expires in 41h.
Four-eyesReview
RTC
Rate card v5 draft awaiting Finance sign-off
Anthropic list rises 12% on 1 Sep. Blended margin falls 61.4% → 57.3% if v5 does not publish first. 31 tenants are pinned to v4 and keep it until renewal either way.
TRL
Tanjong Aqua Farms · trial ends in 12 days, 2 of 5 activation milestones
Day 18 of 30. 380 promotional credits remain and expire with the trial. No contact logged by A. Wong in 11 days.
PRV
Privileged access review · 7 impersonation sessions unreviewed
Oldest is 6 days old. The control only operates if somebody reviews it, so this is an evidence gap rather than an administrative chore.
7 sessionsReview
LIF
Novena Partners · retention window closes 28 Sep, deletion not scheduled
Churned 30 Jun. Both gates are four-eyes, the legal hold must be absent, a final export must be offered, and anything wGrow still owes them must be discharged before deletion completes. Their availability service credit remainder was discharged in cash on 18 Jul, so nothing outstanding blocks the gate — schedule the deletion rather than letting the window close unattended.
CNV
Sentosa Wealth Partners · trial converted, order form signed 14 Aug
Professional plan, 24 seats, 500,000-credit bundle. The promotional lot expires and the purchased lot grants on payment confirmation, not on provisioning.

Money, month to date

Credits sold
4,180,000
Cash received
S$38,240
Credits consumed
5,184,000
Revenue recognised
S$47,180
COGS
S$18,210
Gross margin
S$28,970
Credit liability
S$182,400
Overdue receivables
S$21,660
Daily consumption, 14 days

Peak 14 Aug — 486,200 credits, driven by Meridian Capital's quarterly attestation batch.

Value out, awaiting approval

Impersonate · scope read_content
Meridian Capital Advisors · a.wong · expires 22m
High sens.
Cash refund · S$1,240
Ridgeway Legal LLP · k.ong · expires 41h
Second Op
Goodwill grant · 2,200 credits
Ridgeway Legal LLP · k.ong · expires 47h
Second Op
Suspend tenant (commercial)
Harbourfront Legal · k.ong · expires 4d
Second Op
Publish rate card v5
k.ong · expires 6d
Second Op

Collections

Harbourfront Legal
INV-2026-0418 · 41 days overdue
S$18,400
Kallang Trading
INV-2026-0377 · 68 days · suspended
S$2,410
Straits Content Co
INV-2026-0429 · 6 days overdue
S$850
Model providers · today

Anthropic

Degraded
P95 latency
4,820 ms
Error rate
3.4%
Spend today
S$412.60
Share of COGS
58%

OpenAI

Healthy
P95 latency
1,140 ms
Error rate
0.2%
Spend today
S$96.40
Share of COGS
14%

Google

Healthy
P95 latency
1,610 ms
Error rate
0.4%
Spend today
S$74.10
Share of COGS
11%

Azure OpenAI (SG)

Healthy
P95 latency
1,380 ms
Error rate
0.1%
Spend today
S$118.90
Share of COGS
17%

Tenant directory

Every customer wGrow has, with the money position visible before you open anything. Runway — projected days until credits are exhausted at trailing-14-day burn — is the leading indicator; balance on its own tells you nothing.

Search & saved views

13 of 38 shown
Saved views
All tenants Active & paid Runway under 14 days Trials ending ≤ 7 days Past due Suspended Churned — deletion due High sensitivity BYOK
Filters
state: any plan: any region: SG · MY · ID owner: any health: any tier: shared · dedicated · vpc

Tenants

3 under 14d runway1 past dueSorted by runway ascending
TenantStatePlanCredit balanceRunwayMRRHealthOwner
Tanjong Aqua Farms
tnt_01HS4B…tanjong
TrialTrial — Starter caps
trial ends 27 Aug
380 promo · S$3.80 2d212/day
64
A. Wong
Harbourfront Legal
tnt_01HR2K…harbourfront
Past dueProfessional 12,400 · S$124 4d2,937/day S$3,800
33
R. Lee
Sentosa Wealth Partners
tnt_01HS7C…sentosa
TrialTrial — converting
order signed 14 Aug
4,800 promo · S$48 11d436/day
79
K. Ong
Bukit Timah Accountancy
tnt_01HQ4D…bukittimah
ActivePractice
auto-topup off
46,800 · S$468 18d2,600/day S$1,400
71
A. Wong
Pasir Panjang Logistics
tnt_01HQ8F…pasirpanjang
ActiveProfessional 61,500 · S$615 27d2,278/day S$2,600
74
A. Wong
Ridgeway Legal LLP
tnt_01HQ7X…ridgeway
ActiveProfessional 161,014 · S$1,610 38d4,280/day S$4,200
82
K. Ong
Straits Content Co
tnt_01HQ9M…straits
ActivePractice 162,180 · S$1,622 51d3,210/day S$900
48
R. Lee
Clementi Medical Group
tnt_01HP9J…clementi · VPC · high sensitivity
ActiveRegulated 341,600 · S$3,416 63d5,422/day S$8,400
84
R. Lee
Meridian Capital Advisors
tnt_01HP2S…meridian · high sensitivity
ActiveRegulated 592,000 · S$5,920 83d7,163/day S$11,500
88
K. Ong
wGrow Internal
tnt_00000001…wgrow · internal_billing
ActiveInternal 2,400,000 · not billed n/aexcluded from revenue
91
Platform
Kallang Trading Pte Ltd
tnt_01HN6R…kallang
SuspendedPractice −1,500 · overdraft, S$15 suspended 12 Jul · overdraft recovers from next grant S$0
12
R. Lee
Novena Partners
tnt_01HK3T…novena
ChurnedProfessional (ended) 0 · lots expired Deletion due 28 Sep S$0 K. Ong
Toa Payoh Advisory
crm_opp_4417 · no tenant infrastructure
LeadQuoted — Professional A. Wong
38 tenants · 34 active · 27 paid · 7 trial · credit liability S$180,694 · blended margin 61.4% · 3 accounts below 14-day runway · 1 lead not yet provisioned. Credit liability counts unspent credits only: Kallang’s 1,500-credit overdraft is money owed to wGrow rather than value held for a customer, so it is excluded rather than netted off. Runway is computed nightly from trailing-14-day consumption and does not account for scheduled batch work due after the projection window.

Ridgeway Legal LLP

Cloud Dedicated (Singapore) · signed 14 Mar 2026 · renews 14 Mar 2027 · owner K. Ong. This pane is the operator view; it shows margin, COGS and lot rates the customer never sees.

State
Active
Plan
Professional · 50 seats
Credit balance
161,014 S$1,610
Runway
38d
MRR
S$4,200
Gross margin
63.9% +1.4pt
Rate card
v4 pinned
Users
33 / 50
4 added in the last 30 days
Crews in production
6
of 25 licensed · 2 in supervised sampling
Runs, 30 days
2,914
+18% vs previous 30
Cost per outcome
S$1.44
−18% vs Q1 · baseline S$186 manual
Credits consumed MTD
128,400
Revenue S$1,104 · COGS S$399

Account facts

Internal view
Tenant ID
tnt_01HQ7X…ridgeway
UEN
201933471C
Contract signed
14 Mar 2026
Term
12 months, auto-renew
Renewal date
14 Mar 2027
Deployment tier
Cloud Dedicated
Residency
Singapore only
SSO
Microsoft Entra ID
Data classification
Legal privilege
High-sensitivity flag
No
BYOK
Disabled
Support tier
Business · 4h P1
Secret references are shown by name and rotation status only. No secret value is ever returned to an operator tool. Model gateway key ridgeway/anthropic-sg — platform-managed, rotated 02 Aug 2026, next rotation 02 Nov 2026.

Recent runs

Metadata only · no artefact content without four-eyes
RunCrewOutcomeCreditsCOGSMarginWhen
run_9f21c4LawCrew Document ReviewComplete · 11 nodes458S$2.3141.4%15 Aug 11:47
run_9f2098LawCrew Document ReviewComplete · 11 nodes412S$2.0442.4%15 Aug 10:12
run_9f1f70Conflicts & OnboardingAwaiting partner sign-off96S$0.2866.1%15 Aug 09:38
run_9f1c22Precedent ResearchAbstained · evidence floor184S$0.7155.2%15 Aug 08:04
batch_0815aBulk clause extraction214 runs · hourly settlement11,420S$41.8057.4%15 Aug 09:03
run_9f1804eDiscovery IntakeFailed · connector timeout64S$0.1914 Aug 22:51

Licensed Packs

SG
Singapore Legal Practice Pack v6.3.0
Annual licence · renews 01 Mar 2027 · S$680/month · statutes tracked weekly
Current
FS
MAS Financial Compliance Pack v4.1.2
Annual licence · renews 01 Nov 2026 · S$540/month · 1 source stale
Renewal in 78d
TD
SG Tender Response Pack v2.4.0
30-day evaluation · started 04 Aug · 11 runs used
Trial
RT
KrewOS Cloud Dedicated runtime
Singapore region · dedicated pool pool-sg-04 · concurrency ceiling 24
Provisioned

Contacts

NS
N. Sundaram · Managing Partner
Economic buyer · n.sundaram@ridgewaylegal.example
PL
P. Lim · Practice Technology Lead
Technical contact · day-to-day admin
FN
Finance desk
Billing contact · finance@ridgewaylegal.example
CY
C. Yeo · wGrow
Customer Success owner · last touch 11 Aug

Credit position

Available
161,014 S$1,610
Held in reservations
1,486
Overdraft ceiling
25,000 unused
Expiring within 90 days
2,200
Effective lot rate
S$0.0086
Deferred revenue held
S$1,378.58
Trailing 14-day burn
4,280 /day
Auto-topup
At 50,000 → buy 240,000
Consumption draws promotional and goodwill lots first, then purchased lots by earliest expiry. 2,200 goodwill credits on lot_0402 expire 12 Nov 2026; at present burn they will be consumed within the day and expire holding nothing.

Open items

4
GW
Goodwill grant 2,200 credits
APR-1186 · requested k.ong · ADJ-0244 · expires 47h · needs a second approver
PK
MAS Pack renewal in 78 days
Quote not yet sent · 14% uplift proposed
SP
SUP-1187 · slow precedent retrieval
Open 2 days · one 42-minute support session, closed
MG
Margin finding · routing change
writing-premium is 38% of consumption at 53% margin; routing the summarisation node to research-standard lifts blended margin ~3.1pt, evaluation delta 0.4%

Timeline

Release lawcrew v3.1.0 to production
12 Aug · by p.lim
240,000 credits purchased · INV-2026-0402 paid
09 Aug · S$2,064.00 · 14% volume discount
Autonomy reverted on Precedent Research
06 Aug · review sampling 20% → 40%
Support session by j.lim · 42 min
01 Aug · scope read_content · SUP-1187 · approved p.nair

Provision a new tenant

Turn a signed order form into a correctly configured, isolated, billable tenant in one pass. Nothing is created until the final review step, and any failed provisioning job rolls the whole thing back.

1 · Company & contacts
2 · Plan & rate card
3 · Credit grant
4 · Region & tier
5 · Pack entitlements
6 · Invite admins
7 · Review & provision

Step 3 · Initial credit grant

In progress
This grant is a movement of value, so it is treated as one. It requires a purpose code from the controlled taxonomy, an evidence reference, and — for a payment-backed grant above your 50,000-credit desk limit — a second approver who is not you. The grant does not fire on provisioning; it fires on payment confirmation.
List value S$5,000.00 at 1 credit = S$0.01
14% volume discount · effective rate S$0.0086 per credit
Free text is not accepted here; reporting depends on the taxonomy
Paid purchases sit in deferred revenue until consumed
Enterprise tenants on PO terms usually take the second option
Disabled automatically if the tenant ever reaches past due
Set to zero for strict-prepay contracts
500,000 credits (S$4,300.00) exceeds your 50,000-credit desk limit for payment-backed grants. This grant will route to the four-eyes queue for approval on commit. Self-approval is rejected, as is approval by anyone in your conflict group.

Completed steps

S1
Company & contacts
Sentosa Wealth Partners Pte Ltd · UEN 202144781M · sentosawealth.example verified by DNS TXT 14 Aug · slug sentosa-wealth · admin contact D. Rahman · billing finance@sentosawealth.example · high-sensitivity flag Yes (fund administration)
Valid
S2
Plan & rate card
Professional · 24 seats · 12-month term · SGD · Net 14 · GST standard-rated 9% · rate card v4 pinned, pin expires at renewal · dunning profile Standard
Valid

Remaining steps

S4
Region & deployment tier
Proposed: Cloud Dedicated, Singapore, residency SG-only. Enterprise VPC would branch to a manual estate checklist instead of an automated path.
Not started
S5
Pack entitlements
Proposed: MAS Financial Compliance Pack (annual). Singapore Legal Practice Pack declined at contract.
Not started
S6
Invite administrators
First Tenant Administrator, SSO configuration intent, onboarding template pack, assigned CSM, kickoff date.
Not started
S7
Review & provision
Hard validation gate. Shows the derived configuration, the grant that will fire, the invoice that will be raised, and every object that will be created.
Not started

Summary so far

Draft
Origin
Trial conversion
Trial tenant
tnt_01HS7C…sentosa
Legal entity
Sentosa Wealth Partners
State on commit
Active
Plan
Professional · 24 seats
Rate card
v4 pinned
Initial grant
500,000 credits
Contract value
S$4,300.00
Invoice to raise
S$4,687.00 incl. GST
Requested by
a.wong
Approver
Pending — second approver

What commit will create

tenant            sentosa-wealth        state active
workspace         Fund Administration
environments      dev · staging · prod
secret vault      ns/sentosa-wealth     empty, sealed
search namespace  idx-sg-sentosa
audit stream      aud/sentosa-wealth    append-only
billing account   bil_0714              SGD, Net 14
credit lot        pending payment       500,000 mc-backed
runtime pool      pool-sg-07            concurrency 16
rate card pin     v4 → 14 Aug 2027
Trial artefacts migrate across intact. The 4,800 promotional credits on the trial lot expire at conversion rather than transferring, exactly as the trial terms state.

Guard rails

4E
Four-eyes on commit
Paid production provisioning and the 500,000-credit grant both require a second approver
HS
High-sensitivity flag set
All future impersonation into this tenant will force four-eyes regardless of scope
RB
Rollback on partial failure
Provisioning runs as a visible job list; any red job unwinds every object created
AU
Audit note
Commit writes actor, approver, evidence reference and the full derived configuration to the operator audit trail

Lifecycle action console

State transitions with the consequences shown before commit. Only legal transitions are offered; illegal ones are refused by the state machine rather than merely hidden from the operator.

Tenant lifecycle state machine

Legal paths only
LeadTrialActive· conversion: order form attached, promo lot expires, purchased lot grants
LeadActive· signed order, no trial · four-eyes
ProvisioningProvision failed· any step fails, or 15 minutes elapse · automatic
Provision failedProvisioning· retry · only once cleanup of the partial estate is confirmed
Provision failedPending deletion· abandonment · four-eyes · cleanup confirmed · terminal route
TrialChurned· trial expires unconverted · 7-day and 1-day notices required
ActivePast due· invoice unpaid at due + 14 days · automatic, dunning ladder starts
Past dueActive· payment received · automatic, auto-topup re-enabled
Past dueSuspended· unpaid at due + 45 days · four-eyes · enterprise requires Finance Controller
ActiveSuspended· security incident or abuse · immediate · commercial suspension needs four-eyes
SuspendedActive· payment or security matter closed · four-eyes · reinstatement note required
SuspendedChurned· no resolution within 60 days · write-off decision recorded
ChurnedActive· win-back · four-eyes · data restored if within retention · only where the tenancy has previously held trial or active
ChurnedPending deletionDeleted· 30-day cooling period · four-eyes at both gates · legal hold absent · every obligation owed to the customer discharged
Refused transitions: anything → deleted without passing through pending_deletion; deleted → anything; suspendedrestricted; trialrestricted, because a trial that runs out of promotional credits ends or is extended rather than falling into a payment state; churnedactive where the tenancy has never held trial or active; and any deletion transition while a legal hold is set. Refusal happens at the service layer, and every refused attempt is written to the operator audit stream with the actor, the requested transition and the reason — a refusal is evidence, not a dead end in the interface.
Abandonment is a decision to stop, not a slower retry. A provisioning that cannot be made to succeed does not sit in provision_failed forever. The retry route stays open until abandonment is authorised; once it is, the tenancy is on a terminal route whose only remaining destination is deleted. Such a tenancy can never be won back, because one whose estate was never built has nothing to reinstate — which is exactly the case the churnedactive refusal above exists to catch. Where no tenant data was ever created the final export offer is inapplicable rather than waived, and the certificate of deletion records that there was nothing to export.
A debt owed to the customer never blocks an erasure. Deletion is refused while wGrow still owes the customer money — an unsettled refund, or an unapplied availability service credit remainder carried forward against the billing account. The refusal is bounded and never indefinite: 30 days after the tenant entered churned, deletion proceeds regardless, and the undischarged amount survives as a payable owed to the former customer until it is paid. A sum wGrow owes is not a basis on which wGrow may go on holding personal data.

Proposed transition

Not yet committed
Tenant
Straits Content Co
From
Active
To
Suspended
Class
Commercial · non-payment
Requested by
k.ong · 26m ago
Value at risk
S$850 + S$900 MRR
The dunning ladder has not completed. Straits Content Co is 6 days overdue on INV-2026-0429, not 45, and the normal path is active → past due → suspended. Skipping the ladder is legal but is treated as an exception: it requires a Finance Controller as second approver rather than any second operator, and the reason text is quoted verbatim in the customer notice.
Impact preview

Execution — what stops

Stops
RUN
No new runs admitted
Admission gate refuses with a documented 402 body naming the tenant state
SCH
9 scheduled crews disabled
Including the nightly Content Studio batch at 02:00
API
2 API deployments return HTTP 402
Structured error body, documented, stable across suspensions
WHK
Webhooks disabled
Inbound events queue for 7 days, then drop
ACT
All side-effect Actions blocked
No outbound email, filing or connector write can fire

Data & access — what keeps running

Preserved
RD
Studio becomes read-only
Nothing is hidden; every artefact and evidence chain stays visible
EX
Export remains available for 90 days
Full-fidelity export, no gating on payment
AU
Audit and evidence retained in full
Suspension never truncates the record
KB
Knowledge indexes retained, not refreshed
Sources go stale; the freshness banner in the tenant app says so
SSO
SSO login blocked except Tenant Administrator
2 of 11 users retain access — P. Chandra and the finance desk

Commercial

Continues
SUB
Subscription continues to accrue
S$900/month unless explicitly waived on this screen
CON
Credit consumption stops entirely
COGS exposure falls to zero from the moment of commit
HLD
Held reservations released
1,840 credits returned to available balance
TOP
Auto-topup disabled
Already off — the card declined on 13 Aug
INV
Invoices continue to issue
INV-2026-0429 stays live; the debt is not written off by suspending

In-flight long-running work at commit

Checkpointed and parked, never killed
RunCrewProgressWait stateConsumedTreatment on suspendRecovery
run_a41c07Content Studio · bilingual campaignnode 8 of 12executing1,940Checkpointed, parked as awaiting_creditAuto-resumes on reinstatement within 72h
run_a41ba2Editorial Reviewnode 5 of 7human task assigned 14 Aug610Human step completes first, then parksReviewer keeps the assignment; no SLA breach recorded
run_a41938Client Brief Intakenode 11 of 12executing844Completes into overdraft — past 80% of planMarginal COGS S$0.31; parking it would waste 844 credits of paid work
run_a41770Social Schedulingnode 2 of 6awaiting external callback88Parked; callback queued for 7 daysPartial artefacts committed and visible immediately
Partial results already produced are committed and remain visible to the customer. Parked runs discard at 72 hours; the grace window is extendable on this screen without a second approver because extending grace cannot lose anybody money.

What the customer sees

In-app banner, non-dismissible: “Your KrewOS tenant is suspended. New work cannot start. Your data, evidence and exports remain available. Contact finance@wgrow.example or settle INV-2026-0429 to restore service.”
Email to the billing contact and the technical contact at commit, quoting the reason text verbatim, the outstanding amount, the parked-run count and the 72-hour grace deadline.
API consumers receive HTTP 402 with {"error":"tenant_suspended","reinstate_by":"payment"} — a documented, stable contract, not a generic 403.

Suppressing notice is possible only for security suspensions under an active fraud investigation, requires Security & Compliance approval, and raises a notice suppressed flag on the tenant that persists until reviewed.

What is reversible

YES
The suspension itself
Reinstatement to active on payment, under four-eyes, with a reinstatement note
Fully
YES
Parked runs, within 72 hours
Resume from the last checkpoint with no loss
Fully
PRT
Parked runs, after 72 hours
Transition to expired_unfunded; partial artefacts kept, execution state released
Partly
PRT
Queued inbound webhook events
Replayable for 7 days, dropped after
7 days
NO
Missed scheduled runs
The nightly batch simply does not happen; it is not backfilled
No
NO
The customer notice
Once sent it cannot be unsent, which is why the preview is mandatory
No

Reason, notice and approval

Value-movement action
463 characters · exact repeats of your last three reason texts are rejected
k.ong is the requester and cannot approve. Skipping the ladder needs a Finance Controller, and r.lee is the only one — the bottleneck rule 4 flags on Operator roles. If r.lee is unavailable the request waits or goes to break-glass.
// audit record written on commit — append-only, hash-chained
transition   active → suspended        class: commercial
tenant       tnt_01HQ9M…straits
actor        k.ong                     Billing Operator
approver     r.lee                     Finance Controller · distinct person
reason       non_payment               COL-0342
notice       sent 15 Aug 12:04         billing + technical + in-app
runs_parked  3                         checkpointed at last commit
held_released 1,840 credits
reversible   yes → reinstate to active, four-eyes
Committing sends the customer notice immediately and cannot be undone from this screen. Reinstatement is a separate transition with its own four-eyes gate. Suspending does not write off the debt and does not delete anything.

Support access & impersonation

Privileged access into a customer tenant, time-limited, reason-bound and fully audited, per FR-ADM-009. The point of this screen is not to make support access easy; it is to make every use of it provable.

IMPERSONATION ACTIVE · Ridgeway Legal LLP · j.lim · scope read_content · SUP-1187 · 23:14 remaining · every action recorded and written to the customer's own audit stream · End session

Request access

Four-eyes may apply
High-sensitivity tenant — four-eyes forced on every scope
Validated against the support system; free-text ticket references are rejected
271 characters · minimum 40 · exact repeats of your last three justifications are rejected
Default is the narrowest scope. read_content and act_as_user always require four-eyes.
There is no indefinite option. Extension requires fresh justification and re-approval.
Meridian Capital Advisors carries the high-sensitivity flag. This request routes to a Support Engineering approver who is not j.lim, expires unapproved in 4 hours, and posts to the security channel within 5 seconds of approval.

Active session imp_2304

23:14 remaining
Tenant
Ridgeway Legal LLP
Operator
j.lim · Support Engineer
Scope
read_content
Approved by
p.nair · 11:58
Granted
60 min
Elapsed
36:46
Session budget
Ticket
SUP-1187
Identity in use
support@krewos
Customer notified
Yes · 11:58, in-app and email
Actions so far
34 reads · 0 writes
Recording
Full request index, retained 400 days
Five-minute warning
At 55:00 · extension needs fresh justification
Every request in this session is tagged with imp_2304 and written to Ridgeway Legal's own audit stream. The customer sees this session in their console while it is happening, not afterwards.

Scope limits in force

read_content
RD
Read configuration and run graph
Crew definitions, releases, autonomy settings, budgets
Allowed
RD
Read artefacts, evidence and prompts
The reason this scope needed a second approver
Allowed
WR
Any write
Blocked at the gateway, not merely hidden in the UI
Blocked
ACT
Trigger runs or side-effect Actions
Requires act_as_user with written customer authorisation
Blocked
FIN
Any credit or billing movement
Nobody who can impersonate can also move money
Denied by role
EXP
Export or download
Support sessions cannot remove data from the tenant
Blocked

Masked in every session

Always
SEC
Secret values
Name, rotation date and status only — never the value, in any scope, for any role
SSO
SSO tokens and session cookies
Redacted from request logs and from the session recording index
PII
Client identifiers in privileged matters
Hashed unless scope is read_content and the tenant's privilege policy allows it
PAY
Payment instrument details
Last four digits and expiry only, sourced from the processor
KEY
BYOK provider keys
Reference and health status only

Recent sessions

SessionTenantOperatorScopeTicketReasonGrantedUsedApproverActionsNotifiedReviewed
imp_2304Ridgeway Legal LLPj.limread_contentSUP-1187 Precedent retrieval latency; comparing evidence chain against reported timings 60m36mp.nair34 r · 0 wYesLive
imp_2291Straits Content Coa.wongact_as_userSUP-1179 Resumed two runs stuck behind a revoked connector token, at customer's written request 30m29mm.chan6 r · 2 wYesUnreviewed 6d
imp_2288Meridian Capital Advisorsj.limread_contentSUP-1174 Attestation batch settlement query — 18,000 credits disputed 60m51mm.chan62 r · 0 wYesUnreviewed 4d
imp_2286Clementi Medical Groupj.limread_metadataSUP-1168 VPC agent heartbeat gap; confirming runtime pool version from reported telemetry 30m8m— auto11 rYes✓ 30 Jul
imp_2279Harbourfront Legalj.limread_metadataSUP-1160 Confirming which runs parked when credits exhausted, at k.ong's request ahead of the collections call 15m15m— auto9 rYes✓ 28 Jul
imp_2271Bukit Timah Accountancya.wongread_metadataSUP-1154 Auto-topup failure diagnosis — confirming threshold configuration, not card data 15m4m— auto5 rOn closeSampled
imp_2264Kallang Trading Pte Ltda.wongread_metadataSUP-1141 Pre-suspension check of parked run count and export readiness, at r.lee's request 15m11m— auto7 rYes✓ 14 Jul

Control evidence

FR-ADM-009 · §30.1
// what a completed session leaves behind
session        imp_2291
tenant_stream  aud/straits-content      customer-visible
operator_trail ops/privileged-access    append-only
justification  stored verbatim, 214 chars
approver       m.chan                   ≠ actor, ≠ conflict group
request_index  8 entries, 400-day retention
writes         2                        both authorised in SUP-1179
review         required within 5 working days

Who may do this at all

Support Engineer
Standard impersonation directly; high-sensitivity tenants need four-eyes
Yes
Customer Success Manager
Standard impersonation under four-eyes; no high-sensitivity access
Four-eyes
Billing Operator · Finance Controller
Zero impersonation, zero content access — they move money instead
Never
Platform Engineer
Infrastructure control only; no route into tenant content
Never
Platform Security Reviewer
Reviews these sessions and cannot grant access to anyone, including themselves
Reviewer only
Operator Owner
Break-glass only · second Owner's live confirmation · 60-minute expiry · mandatory post-hoc review that blocks period close
Break-glass

Legal holds & data subject requests

The two obligations that reach across every store at once. A legal hold is an object with its own scope, never a flag hung on something else — because a flag cannot say what it covers, who placed it, or which matter it serves, and all three are what a court asks for.

Holds in force
3
2 matters · 1 regulatory
Tenants in scope
2
Flag set under FR-TEN-008
Deletions suppressed
63
Each refused by name, each recorded
DSRs open
2
Clock: 11 and 24 days remaining
Cooling periods held
1
Novena Partners · countdown paused
A hold suspends; it never deletes, and it never silently swallows a deletion either. While a hold is in force every retention-driven expiry, every erasure and every deletion within its scope is refused by naming the hold rather than failing quietly, and each refusal is written down (FR-GOV-015). On release, suspended retention deletion resumes only after a recorded review — it is never executed retroactively, because three months of deletions firing at once is how a release becomes an incident.

Legal holds

In forceAll tenants3
HoldMatterScopeCustodianPlaced byPlacedSuppressedState
LH-2026-004Tanglin Holdings arbitration
SIAC 2026/114
Tenant ridgeway · Legal workspace
Runs, Artefacts, Evidence, Memory
N. Sundaramd.rahman12 Jun41In force
LH-2026-006MAS thematic review
Regulatory · no matter number
Tenant meridian · all workspaces
Runs, audit, knowledge sources
P. Chandrad.rahman28 Jul19In force
LH-2026-007Employment claim
Named data subject
Data subject ds_0912
Across every store that holds them
P. Chandrad.rahman03 Aug3In force
LH-2026-002Kallang contract dispute Tenant kallang · one Run C. Yeod.rahman14 Mar7Released 02 Jul
Scope is expressed over whatever the matter actually reaches — a tenant, a workspace, a project, a Crew, a single Run, an Artefact, an Evidence set, a knowledge source or a named data subject. LH-2026-007 holds a person rather than a container, which is why it survives the deletion of any one matter they appear in.

Suppressed deletions · LH-2026-004

41 recorded
WhenWhat would have been deletedDriverRefusal
14 Aug 02:0041 session memory records
Legal workspace · matter close + 90d
Retention · FR-OPS-009Held by LH-2026-004
09 Aug 02:006 Run traces beyond the 90-day windowRetention · FR-OPS-009Held by LH-2026-004
02 Aug 11:14Artefact export purge, requested by tenantTenant deletion · FR-ADM-010Held · requester notified
21 Jul 02:00Evidence set for RUN-8D2201Retention · FR-OPS-009Held by LH-2026-004
The third row matters more than the others: a customer asked for something to be deleted and was refused. They were told, and told why — a silent refusal here is the difference between a defensible hold and a data protection complaint.

Release · LH-2026-004

Blocked
Requested by
d.rahman · Security & Compliance
Second authoriser
Required
May not be
N. Sundaram — custodian
Reason
Recorded, mandatory
Closure reference
Matter closure required
Release needs the Platform Security Reviewer and a second authoriser who is not the custodian, with a reason and the matter's closure reference (FR-GOV-017). The custodian is excluded for the obvious reason: the person holding the evidence should not also be the person who decides it is no longer needed.
On release, the 41 suppressed deletions do not simply execute. They enter a recorded review, and the retention clock resumes from there.

Effect on the tenant lifecycle

FR-GOV-016
Churned Pending deletion Deleted
Entry to pending_deletion is refused outright while a hold covers the tenant. A tenancy cannot begin its exit while the evidence inside it is under order.
Novena Partners. A hold landed on day 12 of the 30-day cooling period, so the countdown is suspended for the life of the hold. On release it resumes with 18 days remaining and a re-issued final export offer — the customer does not lose the notice they were owed because a matter intervened.

Data subject requests

PDPACore2 open
Targeted for Core (FR-GOV-012, FR-GOV-013). The intake and the statutory clock are shown here because they govern the same stores the holds do, and the two interact: an erasure request that meets a hold is suspended by it, not refused on its own merits.
RequestTypeSubjectTenantIdentityDiscoveryClockState
DSR-0041Accessds_0912Ridgeway Legal LLP Verified9 of 11 stores11dRedaction review
DSR-0043Erasureds_1044Straits Content Co Verified11 of 11 stores24dAwaiting execution
DSR-0038Erasureds_0912Ridgeway Legal LLP Verified11 of 11 storesHeldSuspended by LH-2026-007
DSR-0031Correctionds_0877Meridian Capital Advisors VerifiedCompleteClosed 22 JulResponded
Discovery reaches every store. Manifests, Runs, Artefacts, Evidence, knowledge indexes and their embeddings, Memory Records at every tier, logs, traces, exports and backups — each recording its own completion and timestamp, because an erasure that missed the embeddings is not an erasure.
Redaction review is a human step. DSR-0041 stops at 9 of 11 stores because two matters name another individual. Disclosing them wholesale would answer one subject's request by breaching another's.
The clock escalates before it expires. The response pack records what was found, what was disclosed and what was withheld, with the basis for each withholding — and only the audit metadata the law requires survives an erasure, with the basis for that recorded too.

Credit ledger

Every credit movement across all tenants. Append-only, hash-chained and lot-based: one credit is a prepaid claim on S$0.01 of platform services, and margin is computed on the rate the customer actually paid, never on list.

Ledger is append-only. Last integrity check 15 Aug 02:00 — 4,182,904 entries, hash chain intact, all 34 tenant balances reconcile to the sum of their entries. A divergence blocks new grants and raises Sev 1 (NFR-FIN-001).

Query

Saved:All adjustments this monthGrants without invoiceHolds older than 24hNegative balancesSettlement variance >20%
Amount ≥ 1,000 creditsApprover presentEstate: productionrate_card = v4
Entries matching
4,182
Credits in
+4,180,000
Credits out
−3,412,000
Net movement
+768,000
Cash received
S$35,948.00
Adjustments
11 · 34,200 cr all approved

Entries

Chain verifiedNewest first · page 1 of 210
TimeEntryTenantTypeReference CreditsAvailable afterLotActor · approverHash
15 Aug 11:47:31led_0091847Ridgeway Legal LLPhold_releaserun_9f21c4+142161,014lot_0417runtime9f2a·c410
15 Aug 11:47:31led_0091846Ridgeway Legal LLPconsumptionrun_9f21c4 · cp-4−91160,872lot_0417runtime3b71·88ea
15 Aug 11:46:20led_0091844Ridgeway Legal LLPconsumptionrun_9f21c4 · cp-3−30160,872lot_0417runtimec0d4·1192
15 Aug 11:45:02led_0091841Ridgeway Legal LLPconsumptionrun_9f21c4 · cp-2−284160,872lot_0417runtime71ae·3f08
15 Aug 11:43:26led_0091838Ridgeway Legal LLPconsumptionrun_9f21c4 · cp-1−53160,872lot_0417runtime5cc9·0d77
15 Aug 11:42:03led_0091835Ridgeway Legal LLPholdrun_9f21c4−600160,872runtime18f0·b6c2
15 Aug 11:31:08led_0091812Kallang Tradingoverdraft_consumptionrun_7b02e1−340−1,840overdraftruntimea4e7·5501
15 Aug 10:04:52led_0091774Straits Content Cograntauto_topup_0091 · INV-2026-0431+120,000162,180lot_0431system6d18·9ba3
15 Aug 09:12:40led_0091702Meridian Capital Advisorsholdrun_4c88aa−18,000592,000runtime2c55·71fd
15 Aug 09:03:11led_0091688Ridgeway Legal LLPconsumptionbatch_0815a · 214 runs−11,420161,472lot_0417runtimebb04·6f31
14 Aug 17:22:06led_0091402Ridgeway Legal LLPadjustment_creditADJ-0231+2,200161,472lot_0402k.ong · r.lee8ab3·2e19
14 Aug 09:00:00led_0091301Kallang Tradingexpirylot_0298−6,400−1,500lot_0298system44d9·af26
13 Aug 16:40:21led_0091244Harbourfront Legaladjustment_debitADJ-0229−8,00012,400lot_0405r.lee · m.chan0f62·c8d3
12 Aug 10:15:02led_0091090Meridian Capital AdvisorsgrantINV-2026-0425+600,000610,000lot_0433k.ong7e40·1a5b
11 Aug 11:02:18led_0090955Harbourfront LegalrefundCRN-2026-0008−5,00020,400lot_0405k.ong · r.leeb7c1·4e88
28 Jul 09:00:00led_0088140Tanjong Aqua Farmspromo_grantTRIAL-0087+4,2004,200lot_0428c.yeoe11c·70b5
Read the balance column carefully. A consumption entry draws from held credits, not from available, so the available balance does not move until the unused remainder of the reservation is released. Four consecutive settlements at 160,872 is the ledger behaving correctly, not a stuck figure. The column reconciles to the lot inspector below: Ridgeway's two lots hold 162,500 credits, less the 1,486 still held against in-flight runs, gives the 161,014 this column closes on. Available is never the lot balance and the two are only equal when nothing is running.

Worked sequence · one LawCrew Document Review run

run_9f21c4rate card v4settled

Ridgeway Legal LLP, 15 August, 11 nodes. Trailing-30-day distribution for this Release: median 412 credits, P90 520, compiler worst case 1,240. The runtime reserves P90 × 1.15 = 598, rounded up to 600, then settles at each checkpoint FR-RUN-002 already writes and releases what it did not use.

TimeEntryNodesCreditsAvailableHeldCOGS
11:42:00opening position161,4721,486
11:42:03holdreservation, P90 × 1.15−600160,8722,086
11:43:26consumption cp-1n1 intake classify · n2 split & OCR−53160,8722,033S$0.14
11:45:02consumption cp-2n3–n6 clause extraction (join) · n7 risk analysis−284160,8721,749S$1.33
11:46:20consumption cp-3n8 precedent retrieval · n9 conflict check · n10 partner review−30160,8721,719S$0.04
11:47:31consumption cp-4n11 report generation · orchestration · runtime seconds−91160,8721,628S$0.80
11:47:31hold_releaseunused remainder of the reservation returned+142161,0141,486
Run total11 nodes · 4 settlement entries · 1 release−458S$2.31
Settlement is per checkpoint rather than per run for two reasons: a run parked three days at a human task must not hold three days of unsettled liability, and a run that later fails must still have committed the credits it already consumed (FR-RUN-012). The reaper releases any hold whose run has been terminal for 15 minutes, or whose run cannot be located at all — a leaked hold is functionally identical to taking the customer's money (FR-CRD-007).

Lot-based margin

lot_0417

Every consumption entry names the lot it drew from. Revenue is recognised at that lot's effective rate — cash received divided by credits issued — not at the S$0.01 list price. This is the single most common way SaaS margin reporting is wrong.

Credits consumed
458
Value at list (S$0.0100)
S$4.58
Lot drawn
lot_0417
Cash received for lot
S$2,064.00
Credits issued in lot
240,000
Effective rate
S$0.008600
Revenue recognised
S$3.94
Provider COGS
S$2.08
Retrieval, tool, runtime
S$0.23
Gross margin
S$1.63 · 41.4%
Computed at list this run reports 49.6%. The 14% volume discount on lot_0417 is real money that was never received, so reporting on list would overstate this run by 8.2 points — and overstate the whole book by roughly the average discount.

Lot inspector

6 open lots on this query
LotTenantSourceRemainingRate
lot_0417Ridgeway Legalpurchase160,3000.008600
lot_0402Ridgeway Legalgoodwill2,2000.000000
lot_0433Meridian Capitalpurchase, invoiced600,0000.008600
lot_0431Straits Contentauto-topup120,0000.008600
lot_0405Harbourfront Legalpurchase12,4000.008600
lot_0428Tanjong Aqua Farmstrial promo3800.000000
Remaining is gross of holds. A reservation against an in-flight Run reduces available without touching the lot it will eventually draw on, so every figure in this column sits at or above the available balance the ledger reports for that tenant. Consumption draws promotional lots first, then goodwill, then purchased lots by earliest expiry — so the customer realises the value of expiring free credits before paying for anything (FR-CRD-005).

Net movement · 14 days

+768,000
Peaks are grants: 600,000 to Meridian Capital on 12 Aug, 120,000 auto-topup to Straits Content today.

Credit adjustment

Move credits deliberately, with a reason that survives an audit, and never by accident. Adjustments are ledger entries: they cannot be edited or deleted, only offset by a compensating entry that is itself audited.

1 · Tenant
2 · Direction
3 · Purpose
4 · Amount
5 · Lot terms
6 · Evidence & approval
7 · Commit
Tenant
Ridgeway Legal LLP Active
Available
161,014 S$1,610
Held
1,486
Overdraft ceiling
12,840 unused
Runway
38 days healthy
Last adjustment
14 Aug · ADJ-0231 · +2,200

Adjustment

ADJ-0244 (draft)Awaiting second approver
High-sensitivity tenants force four-eyes on every direction.
Debit and Expire early are irreversible reductions in a customer's prepaid claim.
Free-text reasons make reporting impossible, so the code is mandatory and the text is additional.
Validated against the incident register. A free-text reference is rejected.
Rejected if it exactly repeats any of your last three justifications.
Goodwill default. An apology is not a store of value, so it lapses.
This screen issues goodwill, not an availability service credit. They are different instruments and only one of them is discretionary. Goodwill grants credits into a lot that expires, is never cash-refundable, and is issued at an operator's judgement under the ceiling in FR-TEN-013. An availability service credit is money against the next invoice: it creates no lot, carries no expiry, is computed rather than judged, and is discharged in cash if the tenant leaves before it is used up (FR-BIL-020). If you are here because a monthly availability commitment was missed, you are in the wrong place — that credit is issued automatically from the determination on the invoice workbench and needs no adjustment at all.

Resulting ledger entry · preview

Written only on approval
CreditLedgerEntry · append-only, hash-chained
  entry_id          assigned at commit — provisionally led_0091903
  type              goodwill_grant
  tenant_id         tnt_01HQ7X…ridgeway   Ridgeway Legal LLP
  lot_id            lot_0446              new lot, created by this entry
  amount_mc         +2,200,000            2,200 credits · 1 credit = 1,000 mc
  balance_after_mc  163,214,000           163,214 credits available
  cash_received     S$0.00                zero cash · contra-revenue
  effective_rate    S$0.000000            margin on consumption from this lot is 100% negative
  rate_card_version v4
  reason_code       goodwill_incident
  evidence_ref      INC-0231
  actor_id          k.ong                 Billing Operator
  approver_id       r.lee                 Finance Controller · pending
  prev_hash         3b71…88ea
  created_at        set at commit

CreditLot lot_0446
  source_type       goodwill
  original_mc       2,200,000
  remaining_mc      2,200,000
  refundable        false
  revenue_treatment contra_revenue
  expires_at        2026-11-13           notices at T−30, T−7, T−1
Irreversible and permanently audited. Once committed this entry can never be edited or removed. A mistake is corrected only by a compensating entry, which is itself an adjustment requiring its own reason, evidence and second approver — so the error and the correction both stay visible forever (FR-CRD-002).
Where this lands. The entry writes to Ridgeway Legal's own audit stream, so the customer sees the grant and its reason in their console. It also appears in the operator audit trail with before and after balances, and in the cross-tenant audit search under credit.adjustment.

Approval routing

Four-eyes required
2,200 credits (S$22.00 at list) exceeds the goodwill ceiling, configured here at its default of 2,000 credits — S$20.00 at the fixed credit value (FR-TEN-013). This request needs a second approver holding Billing Operator or Finance Controller. It expires in 48h and must then be re-raised.
The ceiling is applied to the day's running total, not to this grant alone. Goodwill to one tenant is summed per operator per day and the ceiling re-tested against that total, so four grants of 600 are the same control event as one of 2,400. You have granted Ridgeway Legal 0 credits today; this request therefore tests at 2,200 rather than at some remainder. Splitting a grant to stay under the line is not a workaround, it is a detected pattern.
Self-approval is not offered, and approvers sharing a reporting line with the requester are excluded for financial approvals.
Drafted Second approval Ledger entry Tenant notified

Authority ceilings

BandValueAuthority
≤ ceiling (2,000 default)S$20.00Support Eng, CSM, Billing Op — single
2,001 – 50,000S$500.00Billing Op or Finance Ctl — four-eyes
> 50,000 creditsS$500.00+Finance Ctl — four-eyes, Owner notified
Any debit (clawback)anyBilling Op or Finance Ctl — four-eyes always

Position after commit

Available now
161,014
This grant
+2,200
Available after
163,214
Held (unchanged)
1,486
Runway 37.6d →
38.1 days
Lots after
3 (was 2)
Contra-revenue this month
S$18.92
Goodwill YTD, this tenant
S$61.12
Goodwill against this tenant is 0.23% of their lifetime billed S$26,840 year to date, and 0.31% once this grant commits. Precedent lookup finds two prior grants, both incident remediation, both approved by r.lee.

Related

INC
INC-0231 · Model Gateway
Sev 2 · 6 tenants · 41 runs failed
4EY
Four-eyes queue
9 pending · oldest 4d
LDG
Ridgeway Legal ledger
2 lots · chain verified 02:00

Rate cards

The credit is a monetary unit, so model price movement has to live somewhere else. It lives here: a versioned mapping from metered resource units to credits, pinned per contract, simulated against real volume before anyone signs off.

Publishing does not move anybody. A tenant's contract pins a version for its term; publishing v5 leaves all 31 pinned tenants on v4. Migration is a separate, deliberate action per tenant or cohort, with a computed notice period. In-flight runs complete on the version pinned at admission, exactly as they complete on their originating Release (FR-RUN-013, NFR-FIN-003).

Versions

v5 draftPublication is two-person
VersionStatusEffectiveTenants pinnedBlended marginAuthorApprover
v5draft01 Oct 2026064.8% modelledk.ong · 11 Augawaiting r.lee
v4current01 Jul 20263161.4% actualr.lee · 12 Junm.chan · 12 Jun
v3superseded01 Jan 2026358.9% actualr.lee · 18 Decm.chan · 18 Dec
v2retired01 Jul 20250r.lee · 20 Junp.nair

What triggered v5

Anthropic opus-class +12%, announced 04 Aug, effective 01 Sep. Modelled impact on the current card is −4.1 points of blended margin — 61.4% falls to 57.3% for identical work.
Alias affected
writing-premium
Share of consumption
38%
Current margin on alias
54.7%
Margin after rise, v4
49.3%
Margin after rise, v5
58.1%
Contracts absorbing it
31 pinned to v4
Exposure to renewal
S$4,180 / month
Policy: increases are absorbed within the term and passed at renewal or with contractual notice; decreases are banked as margin and released selectively as negotiated discount. OpenAI mini-class fell 20% on 01 Aug and was banked, worth +1.2 points.

Line editor · v5 draft

18 lines7 changedCredits per unit · 1 credit = S$0.01 list
LineUnitv4 creditsv5 creditsS$ at listActual COGSv5 margin30d volume
writing-premium · input1,000 tokens0.420.48S$0.00480S$0.0021355.6%412M
writing-premium · output1,000 tokens2.102.42S$0.02420S$0.0107555.6%61M
research-standard · input1,000 tokens0.110.11S$0.00110S$0.0004261.8%1.84B
research-standard · output1,000 tokens0.550.55S$0.00550S$0.0021061.8%214M
classify-fast · input1,000 tokens0.0140.012S$0.00012S$0.000019084.2%3.10B
classify-fast · output1,000 tokens0.0580.050S$0.00050S$0.000077084.6%288M
vision-extract · page1 page1.801.90S$0.01900S$0.0071062.6%148k
retrieval query1 query0.060.06S$0.00060S$0.0000985.0%4.2M
knowledge storage1 GB-month380380S$3.80000S$0.4200088.9%610 GB
tool invocation1 call0.500.50S$0.00500S$0.0008283.6%1.1M
action invocation1 call3.003.00S$0.03000S$0.0021093.0%84k
runtime second1 s0.0100.010S$0.00010S$0.000014086.0%18.4M
run orchestration1 run8.008.50S$0.08500S$0.0112086.8%214k
human task1 task5.005.00S$0.05000S$0.00000100%41k
Non-model lines sit at 83–100% margin and are what keep the blended figure above 60% while model margin sits in the fifties. Their COGS is small and stable, which is precisely why they should be visible rather than buried in an "other" row.

Margin simulator · 30 days of real metered volume

16 Jul – 15 Aug3,412,000 credits replayedFloor 55%

Actual UsageRecord volume for the last 30 days is replayed against three scenarios: today's card, today's card once the Anthropic rise lands on 01 Sep, and the v5 draft. Any tenant falling below the configured 55% margin floor is flagged before publication, not after.

Tenant30d creditsMargin now (v4)v4 after risev5 draftCredits for identical workRunway
Ridgeway Legal LLP128,40063.9%59.4%64.6%+6.2%38d 35d
Meridian Capital Advisors214,90058.2%53.8%61.1%+7.4%83d 77d
Straits Content Co96,30066.1%62.9%67.0%+3.1%51d 49d
Harbourfront Legal88,10059.4%55.0%62.2%+6.8%4d critical
Kallang Trading47,90063.2%59.8%64.1%+4.4%suspended
Tanjong Aqua Farms3,820trialtrialtrial+1.9%2d trial ends 27 Aug
Blended · all 34 tenants3,412,00061.4%57.3%64.8%+5.4%
One tenant breaches the floor. Meridian Capital Advisors falls to 53.8% under the price rise on the current card — below the 55% floor — because their crews are writing-premium-heavy. v5 restores them to 61.1%. Their contract permits mid-term migration on 60 days' notice, so the earliest lawful effective date is 14 Oct 2026.
Say it in the customer's terms. Ridgeway Legal would consume 6.2% more credits for identical work; at their current burn of 4,280 credits a day their runway falls from 38 to 35 days. That sentence, per tenant, is the whole point of this screen — a margin percentage nobody outside Finance can act on becomes a number the CSM can put in an email.

Pin map

31 on v4 · 3 on v3
TenantPinExpiresMid-term
Ridgeway Legal LLPv414 Mar 2027Fixed for term
Meridian Capital Advisorsv401 Nov 202660d notice
Straits Content Cov4rolling monthly30d notice
Harbourfront Legalv331 Dec 2026Fixed for term
Kallang Tradingv4rolling monthly30d notice
Tanjong Aqua Farmsv427 Aug 2026trial
Harbourfront Legal is still on v3 at 58.9% blended. Migrating them to v4 at renewal on 31 Dec is worth roughly S$180 a month, and needs no notice because it falls at term end.

Publication gate

2 of 4 met
1
Simulated against ≥30 days of volume
3,412,000 credits replayed · 16 Jul – 15 Aug
Met
2
Per-tenant margin floor checked
1 breach identified, resolved by v5
Met
3
Second approver sign-off
Requested 11 Aug · r.lee · expires in 6 days
Pending
4
Notices generated for migrating cohort
Nothing migrates on publication; 0 notices required
Not needed
Rate card publication is two-person under FR-CRD-019, which routes it — along with every tenant migration and every credit debit — through the same queue as a refund. The request is in the four-eyes queue showing "blended margin +3.4pt, 31 tenants" as its value at risk.

Invoice workbench

Produce, send, track and settle. Singapore GST at 9% on standard-rated supplies, zero-rated export of services with evidence attached, and every void or credit note under four-eyes.

Draft
4
Awaiting approval
1 void
Issued
12 · S$62,458.64
Overdue
S$21,660.00 3
Paid this month
18 · S$38,240.00
Credit notes
2 · S$1,281.00
Availability credits carried
S$0.00 none open

Invoices

All statesSGDAug 2026GST 9% · UEN 201812345K
NumberTenantPeriod / typeSubtotalGST 9%TotalStateAgeNext action
INV-2026-0418Harbourfront LegalJul · subscription + creditsS$16,880.73S$1,519.27S$18,400.00Overdue41dSuspend gate 19 Aug
INV-2026-0421Kallang TradingJul · credit bundleS$2,000.00S$180.00S$2,180.00Overdue23dFinal notice due
INV-2026-0423Straits Content CoJul · overageS$990.83S$89.17S$1,080.00Overdue12dReminder 2 scheduled
INV-2026-0402Ridgeway Legal LLPAug · credit bundle 240,000S$2,064.00S$185.76S$2,249.76Paid6dClosed 09 Aug
INV-2026-0425Meridian Capital AdvisorsAug–Oct · quarterly + 600,000 creditsS$34,500.00S$3,105.00S$37,605.00Issued14dDue 31 Aug · Net 30
INV-2026-0431Straits Content CoAug · auto-topup 120,000S$1,032.00S$92.88S$1,124.88Issued0dCard capture today
INV-2026-0436Ridgeway Legal LLPAug · subscriptionS$4,200.00S$378.00S$4,578.00Issued3dDue 26 Aug
INV-2026-0433Kallang TradingAug · credit bundle, recoveryS$430.00S$38.70S$468.70DraftClears overdraft on payment
INV-2026-0429Tanjong Aqua FarmsAug · trial conversion quoteS$860.00S$0.00S$860.00DraftZero-rated s21(3) · evidence pending
CRN-2026-0011Straits Content CoAug · credit note, duplicate charge−S$900.00−S$81.00−S$981.00Issued1dApplied to INV-2026-0423
Actions available per row: Issue · Send · Record payment · Part-pay · Convert to credits · Place on hold · Escalate to dunning. Void and Credit note are four-eyes and route to the approval queue with the invoice total as value at risk (FR-BIL-006).

Availability service credit · January 2026 determination

99.84% · committed 99.9%Tier 1 · 10%14 tenantsDET-2026-01
Nobody claimed these and nobody had to. January was served at 99.84% against a committed 99.9%, measured by probes run outside this platform, and every tenant whose contract carries the commitment was owed money the moment that figure was published. A remedy paid in expiring credits would not be a remedy — a tenant that cannot consume them before they lapse, or has already left, receives nothing — so this instrument is money against the next invoice. It creates no lot, carries no expiry, and is not goodwill (FR-BIL-019, FR-BIL-020).
TenantCharges, attributedCredits consumedTrailing meanBaseTierCreditState
Meridian Capital AdvisorsS$10,030.00S$3,543.20S$3,180.40S$10,030.0010%−S$1,003.00Applied · INV-2026-0061
Ridgeway Legal LLPS$4,372.00S$2,304.80S$2,383.00S$4,372.0010%−S$437.20Applied · INV-2026-0064
Novena PartnersS$180.00S$96.40S$1,240.00S$540.00 capped10%−S$54.00Discharged in cash 18 Jul
11 further tenants10%−S$2,353.40Applied
Total credited−S$3,847.60Authorised once · DET-2026-01
Why three quantities, and why the greatest. A percentage of subscription pays nothing to a tenant that buys only credits; a percentage of consumption pays nothing to a tenant whose subscription is most of what it pays; and both collapse in exactly the month the platform stopped working. So the base is the greatest of the three and never their sum — which is why nothing here is added together, and why a prepaid tenant that had not yet started consuming is still measured at something.
Meridian's charges are spread, not landed. Their January invoice was S$28,800 for the quarter. It counts here as S$9,600 — one third — plus S$430.00 of a 600,000-credit bundle spread across the period to its lot expiry (FR-BIL-021). Annual and quarterly billing therefore cannot concentrate a remedy in the month the invoice happened to fall, and an order placed after the failure became visible is disregarded entirely.
Novena's base is capped, then paid after they left. Their trailing mean of S$1,240.00 was earned before they downsized; the cap of three times current charges holds the base at S$540.00, so volume from before a downsizing cannot be recovered against an invoice a fraction of its size. They raised no further invoice, so the S$54.00 carried forward untouched to churn on 30 Jun, was set off against S$18.40 still owed, and the net S$35.60 went out as CRN-2026-0009 on 18 Jul — inside the 30 days FR-BIL-020 allows.
Who is not on this table. Straits Content Co and Tanjong Aqua Farms were degraded in January too and are owed nothing, because the availability commitment is a term of a contract rather than a property of the platform: Standard and trial tenancies do not carry it. That is stated on the public trust page in the same words, so a customer cannot discover the limit only when they try to claim against it. A tenant running its own model keys is measured on a smaller consumption figure than one on platform models, because only its platform credits are ever debited.

Invoice detail · INV-2026-0402

Paid 09 AugRidgeway Legal LLPNet 14
Supplier
wGrow Technologies
GST reg. no.
201812345K
Invoice date
09 Aug 2026
Due date
23 Aug 2026
Customer
Ridgeway Legal LLP
UEN
201933471C
Address
9 Battery Rd, Singapore
Currency
SGD
GST treatment
Standard-rated 9%
Payment method
Corporate card ••4417
Paid
09 Aug 2026, 10:15
Lot created
lot_0417
LineDetailQtyUnitAmount
Credit bundleKrewOS credits, list price240,000S$0.010000S$2,400.00
Volume discount14% · 240k tier, approved by r.lee−S$336.00
Subtotal excluding GSTEffective rate S$0.008600 per creditS$2,064.00
GST at 9%Standard-rated supply of services in SingaporeS$185.76
Total including GSTSettled in full 09 Aug 2026S$2,249.76
Line to lot. The credit bundle line created lot_0417 with cash received S$2,064.00 and effective rate S$0.008600. Every consumption entry drawing on that lot recognises revenue at that rate, which is how the ledger and this invoice agree to the cent.
Open tax question. Prepaid credits are treated here as a prepayment for services, so GST falls at the earlier of invoice or payment. If IRAS treats them as a multi-redemption voucher, GST falls at redemption instead. This must be confirmed before volume grows — retrofitting it repricies every issued invoice.

Dunning · Harbourfront Legal

41 daysS$18,400.00
D0
Invoice due
05 Jul · Net 0, issued same day
Passed
D1
Automated reminder
06 Jul · billing contact, delivered
Sent
D7
First chase, CSM copied
12 Jul · c.yeo called, PO number disputed
Sent
D14
Tenant → Past due
19 Jul · auto-topup disabled, in-app banner shown
Applied
D30
Tenant → restricted
04 Aug · held manually, enterprise account, c.yeo negotiating
On hold
D45
Suspend, four-eyes
19 Aug · 4 days away · Billing Op raises, Finance Ctl approves
Pending
Active Past due Restricted Suspended
Restricted stops new runs and new COGS while preserving read, export and every parked run. It is the state that makes a billing dispute an inconvenience rather than an incident, and it reverses the instant payment clears.

Ageing

3 accounts
BucketValueShare
1–14 daysS$1,080.00
15–30 daysS$2,180.00
31–60 daysS$18,400.00
60+ daysS$0.00
Total overdueS$21,660.001.6% of billed YTD

Guard rails on this screen

VD
Void an issued invoice
Four-eyes · reason code · never deletes, issues a reversal
CN
Credit note
Four-eyes · links to the original line and its lot
RF
Cash refund > S$500
Four-eyes · a distinct second approver, no named role · goodwill lots are never cash-refundable
WO
Write-off
Distinct second approver · blocks period close until reasoned
ASC
Availability service credit
Accrual and invoice line need no second approver · the determination already authorised them
One exception to the refund rule above. "Goodwill lots are never cash-refundable" holds for goodwill, and an availability service credit is not goodwill and creates no lot at all — so when a departing tenant's remainder is discharged in cash, the refundable-lot precondition is disapplied rather than failed, and the customer gets no election between cash and credits either, because expiring credits handed to a tenant on their way out are exactly the defect this instrument exists to avoid (FR-BIL-020). That discharge is a credit note, so it comes back under four-eyes whatever its value.

Invoice line taxonomy

Every line derives from the commercial object that created it (FR-BIL-002)
Line typeCreates a lotSignAttributed toRevenue treatment
Platform subscriptionNoPositiveSpread evenly across the period it coversRecognised over the period
Credit bundle purchaseYesPositiveSpread from purchase to the lot's expiryDeferred until consumption
Plan-included or contractual entitlementYesPositiveSpread across the entitlement periodDeferred until consumption
Metered overageNoPositiveThe month whose consumption it chargesRecognised in that month
KrewOS Pack licenceNoPositiveSpread across the licence periodRecognised over the period
Professional servicesNoPositiveMonth of supplyRecognised on delivery
Availability service creditNeverNegativeThe affected month it remediesContra-revenue
Attribution is not the invoice date. A line belongs to the months it funds, so a tenant invoiced once for a year draws against one twelfth of that line in each month rather than the whole of it in January. This is a billing rule required from day one, and it is deliberately not revenue recognition — that answers a different question, arrives later, and does not reach a prepaid entitlement at all. The two are computed independently (FR-BIL-021).
Only one line type is negative. The availability service credit reduces the invoice total, bears no credits, creates no lot, and takes the tax treatment of the supply it reduces. Everything else on this table either creates a lot or charges for something delivered. A line carried on an invoice that is overdue or written off is disregarded in an availability measurement until that invoice is paid, so money wGrow has not received cannot enlarge a remedy wGrow must pay.

Platform health

Is KrewOS working, for whom is it not, and are we inside the error budget. One degraded service is only interesting once you can name the six tenants feeling it — that is the bridge this screen exists to build.

INC-0231 · Sev 2 · Model Gateway degraded. Anthropic SG endpoint returning 529s since 09:41. 6 tenants affected, 214 runs touched, 41 failed. Failover to Azure OpenAI SG applied 09:58; error rate now 0.09% and falling. Open incident · Provider status
Cloud Shared SG
Healthy Pass
2 pools · 22 tenants · saturation 63%
Cloud Dedicated SG
Degraded 1 of 2
rt-ded-ridgeway at 88% · queueing
Enterprise VPC
Reporting 3 of 3
Last heartbeat 41s ago · 5-min interval
Sandbox estate
Idle Pass
Anonymised refresh completed 04:12
Control Plane availability 30d
99.94%
Committed 99.9% · NFR-AVL-001 · +0.04pt of headroom
Run startup P95
3.2s
Target 5s · NFR-PERF-002
Interface P95
1.9s
Target 2.5s · NFR-PERF-001
Error budget remaining
68%
14 of 30 days elapsed · −19pt today
The availability figure on this screen is a commitment, not a target. Every other threshold here is an engineering aim that a spike may revise. 99.9% is not: it is published as a stated commitment, it is measured by probes run outside this platform on infrastructure this platform cannot take down with it, and a month served below it owes money to every tenant whose contract carries it — 10% of the measurement base between 99.9% and 99.5%, 25% down to 99.0%, 50% below that (NFR-AVL-001, FR-BIL-019). Burning the error budget is therefore a billing event as well as an engineering one. Three months below 99.0% in a rolling twelve also lets those tenants leave without penalty, which no service credit buys back.

Service grid

18 service boundaries · 1h window
ServiceStatusP95Errors 1hSaturationTenants affected
Identity & TenantHealthy84ms0.01%
Catalogue & RegistryHealthy112ms0.00%
Manifest & CompilerHealthy640ms0.04%
Studio CollaborationHealthy58ms0.00%
Vibe BuilderHealthy1,420ms0.07%
Model GatewayDegraded2,140ms1.82%
6
Knowledge & RetrievalHealthy208ms0.02%
Tool & Action GatewayHealthy320ms0.11%
Runtime OrchestratorElevated96ms0.03%
Human TaskHealthy74ms0.00%
EvaluationHealthy1,840ms0.09%
Release & DeploymentHealthy240ms0.00%
Observability & AuditHealthy148ms0.01%
Usage Metering & CostHealthy68ms0.00%
Credit LedgerHealthy42ms0.00%
Billing & InvoicingHealthy96ms0.00%
Operator GovernanceHealthy71ms0.00%
Platform Ops & FlagsHealthy55ms0.00%
Enterprise estates report, they are not probed. The shared estate is measured from the telemetry it emits here. Dedicated, customer VPC, hybrid and private estates are shown only where those deployment models are actually in use, and their list and last heartbeat come from the estate registry rather than from this screen (FR-TEN-015). Those estates send a 5-minute heartbeat, and absence of a signal is rendered as "not reporting", never as healthy — a rule this view owns under FR-PLT-002 — because the Operator Plane cannot reach the Execution Plane in those tiers and pretending otherwise is how an outage stays invisible for an hour.

Queue depth

1 threshold breached
QueueDepthOldestLimit
run.admission46s50
model.gateway2181m 48s120
knowledge.retrieval123s100
tool.action62s80
evaluation3122s60
human.task.notify025

Runtime worker pools

80 workers · 48 busy
PoolBusySaturationOldest wait
rt-shared-sg-118/24
41s
rt-shared-sg-212/24
8s
rt-ded-ridgeway7/8
2m 14s
rt-ded-harbourfront2/8
rt-vpc-meridian9/12
1m 02s
rt-sandbox-10/4
rt-vpc-meridian figures are self-reported by the customer's estate agent (v1.8.2, heartbeat 41s ago). wGrow has no live control there; capacity changes are raised as an upgrade-window request.

Per-tenant impact of the Model Gateway degradation

6 tenants
TenantStateTierRuns touchedRuns failedCredits burnt on failuresSLANotified
Meridian Capital AdvisorsActiveEnterprise VPC (SG)68143,100Enterprise 1h P110:04
Ridgeway Legal LLPActiveCloud Dedicated (SG)52112,200Business 4h P110:04
Harbourfront LegalPast dueCloud Dedicated (SG)3461,180Business 4h P110:04
Straits Content CoActiveCloud Shared265940Standard10:04
Kallang TradingRestrictedCloud Shared213580StandardBanner only
Tanjong Aqua FarmsTrialCloud Shared132420Trial10:04
Total214418,420 S$84.20 list5 of 6
173 runs retried successfully after failover at 09:58 and are not remediable. The 41 that failed consumed 8,420 credits before dying — that figure is the goodwill exposure, and it is computed from telemetry rather than estimated, which is what makes the one-click remediation on the incident console safe to offer.

Model providers & spend

The largest cost line and the largest single point of failure are the same four vendors, so they are watched on one screen. Spend MTD S$18,210 against revenue S$47,180 — every point of provider margin is a point of company margin.

Anthropic

Degraded
P95 latency
2,140ms
Error rate 1h
1.82%
Spend today
S$418
Spend MTD
S$8,940
Share of COGS
49.1%
Fallback
Engaged

OpenAI

Healthy
P95 latency
780ms
Error rate 1h
0.06%
Spend today
S$212
Spend MTD
S$5,120
Share of COGS
28.1%
Fallback
Standby

Google Vertex

Healthy
P95 latency
640ms
Error rate 1h
0.04%
Spend today
S$96
Spend MTD
S$2,880
Share of COGS
15.8%
Fallback
Standby

Azure OpenAI (SG)

Healthy
P95 latency
820ms
Error rate 1h
0.02%
Spend today
S$44
Spend MTD
S$1,270
Share of COGS
7.0%
Fallback
Now primary

Spend and margin by model alias

MTDRevenue at realised lot rates
AliasProvider · classMTD volumeCOGSRevenueMarginvs last month
research-standardAnthropic · sonnet-class1.84B in / 214M outS$7,220S$18,91061.8%+4% volume
writing-premiumAnthropic · opus-class412M in / 61M outS$1,720S$3,80054.7%−2% volume
classify-fastOpenAI · mini-class3.10B in / 288M outS$1,240S$9,12086.4%+31% volume
vision-extractGoogle · vision-class148k pagesS$1,050S$2,66460.6%flat
embed-bulkAzure OpenAI SG · embed-class1.02B tokensS$410S$2,18081.2%+9% volume
non-model channelsretrieval · tools · runtime · storage · humanS$6,570S$10,50637.5%
TotalS$18,210S$47,18061.4%
Concentration is the risk, not the price. Anthropic is 49.1% of COGS across two aliases and one endpoint region. Today's incident cost 41 failed runs; the same failure with no Azure fallback configured for research-standard would have cost roughly 900.

Spend · 14 days

S$18,210 MTD
Today is elevated because retries during INC-0231 were paid for twice: the failed call and its fallback.
Retry cost attributable to INC-0231
S$61.40
Recoverable from provider
S$0.00
Goodwill exposure to customers
S$84.20
Total incident cost
S$145.60

Failover chains

1 manual override active
research-standard
Anthropic SGAzure OpenAI SGGoogle Vertex SG
Manual failover applied 09:58 by s.tan, reason "endpoint 529 rate above 1.5% for 8 minutes". No residency change — all three targets are Singapore.
writing-premium
Anthropic SGAnthropic USblocked
Second hop leaves Singapore, so it is blocked for the 4 tenants with a residency constraint and produces a customer-visible note for the rest.
classify-fast
OpenAIAzure OpenAI SG
A manual failover that changes data residency requires a reason, produces a customer-visible note, and is refused outright for tenants whose contract pins a region. Silent cross-border routing is the fastest way to lose a regulated customer.

Announced price changes

1 unresolved
ProviderChangeAnnouncedEffectiveMargin impactResponse
Anthropicopus-class +12%04 Aug01 Sep−4.1pt blendedRate card v5 drafted; route 30% of writing-premium to research-standard
OpenAImini-class −20%28 Jul01 Aug+1.2pt blendedApplied; banked as margin, no rate card change
Google Vertexvision-class +6%12 Aug01 Oct−0.4pt blendedFolded into v5 line vision-extract 1.80 → 1.90
Stated policy, visible on purpose. Increases are absorbed within the contract term and passed at renewal or with notice; decreases are banked and released selectively as discount. Two consequences worth accepting deliberately: a 30% mid-year rise across a major provider costs roughly 12 margin points until renewal, and wGrow must never claim publicly that pricing tracks provider cost.

BYOK · shadow metering

3 tenantsmodel credits zero-rated
TenantAliases on BYOKNotional model costModel credits debitedPlatform creditsOwn key health
Meridian Capital Advisorswriting-premium, research-standardS$2,410041,2000.02% errors
Harbourfront Legalwriting-premiumS$640012,800rate-limited 3×
Kallang Tradingclassify-fastS$8806,4000.00% errors
Two meters, one wallet. Platform credits — orchestration, runtime, retrieval, tools, actions, human tasks — are charged in full under BYOK. Model credits are shadow-metered for visibility only and never debited; there is no percentage governance fee on notional model cost. Harbourfront's rate limiting is their key failing, shown separately so support does not chase a platform fault that does not exist.

Incident console

Run the incident and communicate about it from the same record, with the affected-tenant list computed from telemetry rather than guessed — and turn it into remediated customers in one action.

Incident
INC-0231 Sev 2
State
Monitoring opened 09:41
Commander
a.wong · comms k.ong
Tenants affected
6 of 34
Runs
214 touched · 41 failed
Goodwill exposure
8,420 cr S$84.20
Detectedautomaticalert-4419
Model Gateway error rate 1.82% against a 0.50% threshold, sustained 3 minutes. Anthropic SG endpoint returning HTTP 529.
09:41
Declared Sev 2a.wong
Two or more tenants degraded, no data loss, workaround available. Commander assigned, comms lead assigned, bridge opened.
09:44
Identifieds.tan
Provider-side. Anthropic status page confirms elevated errors in ap-southeast-1 at 09:47. Not a KrewOS regression; no deploy in the preceding 14 hours.
09:52
Mitigation appliedfailovers.tan
research-standard failed over to Azure OpenAI SG. No residency change. writing-premium left on Anthropic — its only second hop leaves Singapore and 4 tenants forbid it.
09:58
Statement publishedk.ongstatus + email + banner
Status page updated, email to 6 affected billing and technical contacts, in-app banner for affected tenants only. 21 minutes from declaration.
10:02
Recovering
Error rate 0.09%. 173 of 214 touched runs retried successfully and completed. 41 runs failed terminally and committed their partial artefacts per FR-RUN-012.
10:14
Remediation proposedawaiting approvalk.ong
Six goodwill grants totalling 8,420 credits pre-filled from the affected-run list. Each requires a second approver before it becomes a ledger entry.
11:20
Resolvepending
Hold open until Anthropic SG error rate is below 0.10% for 60 minutes and all six remediations are approved. Post-incident review due within 5 working days.

Incident → goodwill credit

6 drafts

One click on the affected-tenant list produced six pre-filled credit adjustments. Each proposes an amount equal to the credits that tenant's failed runs consumed before dying — a number taken from telemetry, not negotiated — and each is an independent request requiring its own second approver. Nothing here moves credits until somebody who is not k.ong says so.

DraftTenantFailed runsCreditsAt listReason codeApproverState
ADJ-0243Meridian Capital Advisors143,100S$31.00goodwill_incidentr.leeAwaiting
ADJ-0244Ridgeway Legal LLP112,200S$22.00goodwill_incidentr.leeAwaiting
ADJ-0245Harbourfront Legal61,180S$11.80goodwill_incident— autoWithin ceiling
ADJ-0246Straits Content Co5940S$9.40goodwill_incident— autoWithin ceiling
ADJ-0247Kallang Trading3580S$5.80goodwill_incident— autoWithin ceiling
ADJ-0248Tanjong Aqua Farms2420S$4.20goodwill_incident— autoWithin ceiling
Total6 tenants418,420S$84.202 four-eyes
Why two of six need a second approver. The goodwill ceiling is 2,000 credits (S$20.00). Meridian at 3,100 and Ridgeway at 2,200 exceed it and route to the four-eyes queue; the other four commit on a single authority. The rule is applied per request, not per incident, so nobody can split a large concession into small ones — the system sums same-tenant same-day goodwill and re-applies the ceiling.
Contra-revenue, not cash. All six are non-refundable goodwill lots expiring in 90 days with contra_revenue treatment. Total revenue impact at realised rates is S$72.41; total cash impact is S$0.00. Cash refunds for this incident would need a separate request, four-eyes above S$500.

Customer communications

3 in sync
ST
Status page post
"Elevated error rates on document-analysis models" · 4 revisions
Live 10:02
EM
Email to affected tenants
12 recipients across 6 tenants · billing + technical contacts
Sent 10:04
BN
In-app banner
Shown to affected tenants only · dismissible after resolve
Live 10:03
FU
Resolution note + remediation
Drafted, holds until all six grants are approved
Draft
Communication clock: 21 minutes from declaration to published statement. A reminder fires at 30 minutes of open incident with no customer communication, because the second worst thing in an outage is silence.

Open incidents

30-day view
IncidentSevTitleTenantsState
INC-02312Model Gateway · Anthropic SG6Monitoring
INC-02303Evaluation queue backlog2Investigating
INC-02294Studio autosave latency1Resolved 13 Aug
INC-02243Duplicate run dispatch1Resolved 22 Jul
INC-0224 is the precedent for today's remediation: 14 runs charged twice, 2,200 credits granted to Ridgeway Legal as ADJ-0231, approved by r.lee. Precedent lookup runs automatically on every goodwill draft so amounts stay consistent across incidents.

Feature flags & rollout

Give a capability to some tenants before all tenants, see exactly who has it, and turn it off in one action. Cohort membership is a deterministic hash on tenant ID, so a tenant never silently drifts in or out of a rollout.

Flags registered
18
6 in active rollout
Tenants exposed
34
To at least one non-GA flag: 11
Per-tenant overrides
7
2 expiring within 7 days
Kill switches armed
5
1 disarmed at GA
Rollouts blocked
1
GA promotion awaiting four-eyes

Flag register

Production estateAll ownersExposure vs unexposed error rate shown inline
FlagDescriptionStageExposureError rate exposedUnexposedOwnerKill switch
autonomy_sampling_v2Risk-weighted review sampling instead of flat percentageDesign partners3 tenants · 11 crews0.31%0.34%AI engArmed
vibe_builder_multifileMulti-file edits from a single natural-language instructionInternalwGrow Internal1.90%0.02%StudioArmed
byok_shadow_meteringNotional model cost metering under BYOK · platform credits charged, model credits zero25% cohort8 tenants0.04%0.04%BillingArmed
credit_overdraftBounded overdraft buffer at exhaustion, park instead of killGeneral34 tenants0.02%BillingDisarmed at GA
awaiting_credit_resumeAutomatic resume of parked runs on top-up within the 72h grace50% cohort17 tenants0.06%0.05%RuntimeArmed
estate_upgrade_wavesStaged version upgrades for customer VPC estatesDesign partners2 estates0.00%0.01%PlatformArmed
hub_public_ratingsPublic component ratings and reviewsOff0CatalogueArmed

Cohort builder · byok_shadow_metering

Promotion to GA blocked
Internal Design partners 25% of eligible 50% General availability
Stable across evaluations; a tenant never flickers.
TenantStateEligibleIn cohortReason
Meridian Capital AdvisorsActiveYesYesHash bucket 07 · BYOK on 2 aliases
Harbourfront LegalPast dueYesYesHash bucket 19 · BYOK on 1 alias
Kallang TradingRestrictedYesYesHash bucket 22 · BYOK on 1 alias
Ridgeway Legal LLPActiveYesNoHash bucket 61 · outside 25% window
Straits Content CoActiveNoNoPlatform-managed keys only · nothing to shadow-meter
Tanjong Aqua FarmsTrialNoNoExcluded by rule: trials
GA promotion is two-person. Moving this flag to general availability exposes 34 tenants to a new billing behaviour, which is why it sits in the four-eyes queue with "34 tenants exposed" as its value at risk rather than being a toggle a single engineer can flip on a Friday.

Kill switch

No confirmation dialog
Deliberately unguarded. A kill switch has one job and speed matters more than accident prevention. There is no confirmation step; the reason field is the only gate. Killing a flag creates an incident stub automatically, notifies the flag owner, and writes to the operator audit trail with the exposed cohort attached.

Per-tenant overrides

2 expiring
TenantFlagValueExpiresSet by
Meridian Capital Advisorsestate_upgrade_wavesOn30 Sep 2026s.tan · design partner MOU
Ridgeway Legal LLPautonomy_sampling_v2Off18 Aug 2026j.lim · SUP-1187, customer requested
Harbourfront Legalawaiting_credit_resumeOn20 Aug 2026k.ong · parked runs during dispute
Kallang Tradingcredit_overdraftOffno expiryr.lee · strict prepay after recovery
Overrides carry an expiry by default. Permanent per-tenant overrides are how a platform quietly becomes unsupportable, so the one without an expiry — Kallang's strict-prepay setting — is a commercial term recorded on the contract, not an engineering convenience.

Rollout safety

ERR
vibe_builder_multifile
Exposed 1.90% vs unexposed 0.02% · 95× worse
Regression
P95
autonomy_sampling_v2
Exposed 3.1s vs unexposed 3.2s startup P95
Neutral
CST
byok_shadow_metering
No measurable latency or error delta over 21 days
Safe

Cross-tenant audit search

The screen that answers a regulator, an external auditor or a customer's compliance officer. Structured facets over the immutable audit store, results that carry their own hash-chain verification, and an export the recipient will accept.

This query spans more than one tenant. Multi-tenant audit search and export require Security & Compliance authority (FR-GOV-002). You are acting as d.rahman · Platform Security Reviewer. The search itself is an audited event: it will appear in the operator audit trail with your identity, the query, the result count and a content hash.

Query builder

Saved:All privileged access, 90dSecret access eventsCross-tenant reference attemptsRelease overridesResidency-blocked runsDSR — all events touching subject
Estate: productionInclude system actorscorrelation_id presentExclude read-only page views
Results
1,284 events
Tenants represented
9 of 34
Denied outcomes
61 4.7%
Operator-plane events
218
Chain
Verified to 15 Aug 02:00
Query hash
q·5f21ae90

Results

ImmutableNewest first · page 1 of 65
TimeTenantActorTypeEventSubjectOutcomeCorrelation
15 Aug 11:22Ridgeway Legal LLPj.limoperatorprivileged_session.openedimp_2296 · read_contentsuccessc·8814ff
15 Aug 11:20Ridgeway Legal LLPk.ongoperatorcredit.adjustment.draftedADJ-0244 · +2,200successc·8814f2
15 Aug 10:08Meridian Capital Advisorssystemsystemmodel_policy.blockedrun_4c88aa · residency SGdeniedc·8811a0
15 Aug 09:58s.tanoperatorprovider.failover.manualresearch-standard → azure-sgsuccessc·880f31
15 Aug 09:12Meridian Capital Advisorsruntimesystemcredit.hold.openedrun_4c88aa · 18,000 crsuccessc·880c17
14 Aug 17:22Ridgeway Legal LLPk.ong · appr r.leeoperatorcredit.adjustmentADJ-0231 · +2,200successc·87f4a8
14 Aug 16:40Kallang Tradinga.wongoperatorprivileged_session.writeimp_2295 · 2 writessuccessc·87f209
14 Aug 14:41Harbourfront Legalv.menontenant userrelease.overridelawcrew v3.1.0-rc.1successc·87ee55
13 Aug 16:40Harbourfront Legalr.lee · appr m.chanoperatorcredit.adjustmentADJ-0229 · −8,000successc·87c910
13 Aug 09:47Straits Content Cosystemsystemcapability.quarantinedshipment-booking actionsuccessc·87b022
12 Aug 03:14systemsystemcross_tenant_reference.deniedidx_ridgeway ← tnt_straitsdeniedc·8790c4
11 Aug 11:02Harbourfront Legalk.ong · appr r.leeoperatorcredit.refundCRN-2026-0008 · −5,000successc·8761b7
09 Aug 22:41Kallang Tradinga.wong · appr p.nairoperatorprivileged_session.openedimp_2288 · read_contentsuccessc·8721d9
09 Aug 18:22m.chan · appr p.nairoperatorbreakglass.openedpa_0405 · full estate · 60msuccessc·871e04
07 Aug 08:03Tanjong Aqua Farmssystemsystemsecret.rotatedsec_ref/aqua-sensor-apisuccessc·86d117
Never a secret value. The row above shows a secret reference, its rotation date and its status. The Operator Plane is a support tool, and NFR-SEC-002 forbids secret values in APIs, logs, prompts, manifests, exports and support tools alike. There is no screen anywhere in this plane that can render one.

Export

Sec & Compliance
export_manifest.json
  query_hash      q·5f21ae90
  executed_by     d.rahman · Platform Security Reviewer
  executed_at     2026-08-15T11:44:02+08:00
  tenants         9 · multi-tenant, authority verified
  result_count    1,284
  content_sha256  6ca1…f0b8
  chain_verified  true · to entry 4,182,904
  signature       ed25519:9f31…2ac7
The export is itself an audited event. A recipient can re-verify the content hash and the chain position without trusting wGrow's word for it, which is the difference between an export and a screenshot.

Denied outcomes · 90 days

61 events
EventCountReading
cross_tenant_reference.denied3Isolation held. Should be zero, is investigated at any value.
model_policy.blocked38Residency and allowlist enforcement working as designed.
budget.hard_limit14Fail-closed on new model work and Actions.
approval.self_rejected4Four operators tried to approve their own request.
impersonation.justification_rejected2Boilerplate repeats of a previous justification.
The three cross-tenant reference denials on 12 Aug were a mis-scoped knowledge index in a design-partner build. No data crossed; the control refused the read and the build was corrected the same day. That sentence is what an auditor is actually asking for.

Privileged access review

FR-ADM-009 says privileged support access happens only through explicit, time-limited, audited procedures. A requirement is a claim until somebody reviews every session and signs their name to it — this screen is where that happens, and it is operated by a role that cannot itself grant access.

Sessions 30d
41
Impersonation 34 · production access 7
Unreviewed
7
Oldest 6 days · control lapses at 7
Duration used
18m
Average, of 42m granted
Sessions with writes
4
All scope act_as_user · all authorised
Notification suppressed
0
Requires Sec & Compliance authority
Seven sessions are unreviewed and the oldest is six days old. The control operates only when it is exercised; an unreviewed session is a SOC 2 evidence gap regardless of whether anything improper happened in it. Review closes at seven days, after which the gap is reportable.

Impersonation sessions

30 daysAll operators5 unreviewed
SessionOpenedTenantOperatorScopeTicketGranted / usedApproverActionsNotifiedReview
imp_229615 Aug 11:22Ridgeway Legal LLPj.limread_contentSUP-118760m / 42mm.chan34 reads, 0 writes11:22Unreviewed
imp_229514 Aug 16:40Kallang Tradinga.wongact_as_userSUP-117430m / 29mm.chan6 reads, 2 writesYesUnreviewed
imp_229313 Aug 09:14Meridian Capital Advisorsj.limread_metadataSUP-117930m / 8m— auto11 readsYesd.rahman 14 Aug
imp_229111 Aug 15:02Harbourfront Legalc.yeoread_metadataSUP-116015m / 15m— auto9 readsYesUnreviewed
imp_228809 Aug 22:41Kallang Tradinga.wongread_contentSUP-115260m / 58mp.nair61 reads, 0 writesYesUnreviewed 6d
imp_228406 Aug 10:30Straits Content Coj.limread_metadataSUP-114115m / 6m— auto7 readsYesd.rahman 07 Aug
imp_227904 Aug 14:20Meridian Capital Advisorsa.wongread_contentSUP-113360m / 51mm.chan44 reads, 0 writesYesOver-scoped 05 Aug
Meridian Capital Advisors carries the high_sensitivity flag, so read_content against it forces four-eyes regardless of the operator's role. Scope defaults to read_metadata everywhere; read_content, act_as_user and any duration above 60 minutes each require a second approver on their own.

Review · imp_2288

6 days unrevieweda.wongKallang Trading
Opened
09 Aug 2026, 22:41
Scope requested
read_content
Duration granted
60 minutes (maximum for scope)
Duration used
58 minutes
Approver
p.nair · Operator Owner
Ticket
SUP-1152
Impersonated identity
support@krewos synthetic
Writes attempted
0 blocked by scope
Artefacts opened
61
Customer notified
Immediately, 22:41
In tenant audit stream
Yes
Out of hours
Yes · 22:41
Justification as written
Customer reports two LawCrew runs parked in awaiting_credit and cannot see why.
Need to inspect the run graph, the checkpoint state and the artefacts already
committed to confirm the parking was correct and that partial output was
delivered before advising on top-up. SUP-1152, customer on the phone.
Decision
A note is mandatory for anything other than "Appropriate".

Patterns

1 finding
11
Volume against peer median
a.wong opened 11 sessions against Kallang Trading in 14 days across 4 tickets. Peer median is 2.
Flagged
3
Out-of-hours access
3 sessions opened after 21:00 · all ticket-linked · all notified
Watch
2
Duration requested at maximum
2 sessions asked for the ceiling; average use was 49m of 60m
Watch
0
Repeat access without a new ticket
Every session in the window carries a distinct, validated ticket
Clear
0
Access with no assigned relationship
All operators had an open ticket or an account assignment
Clear
Volume against peer median is where abuse actually gets caught. Eleven sessions across four tickets is not proof of anything — it is a question worth asking a manager, which is exactly what a review control is for.

Privileged financial actions

30 days
ActionActorSubjectValueApproverReview
ADJ-0231 grantk.ongRidgeway Legal+2,200r.leeSigned 15 Aug
ADJ-0229 debitr.leeHarbourfront Legal−8,000m.chanUnreviewed
CRN-2026-0008 refundk.ongHarbourfront Legal−5,000r.leeSigned 12 Aug
CRN-2026-0011 credit notek.ongStraits Content Co−S$981.00r.leeUnreviewed

Production access

1 break-glass
GrantActorReasonWindowConfirmed byReview
pa_0412s.tanINC-0231 failover, runtime pool config60m / 14mincident auto-grantDue
pa_0409s.tanINC-0230 queue backlog, read replica30m / 22mm.chanSigned 13 Aug
pa_0405m.chanBreak-glass · identity provider outage, normal path unavailable60m / 22mp.nair, liveBlocks period close
Break-glass is loud, not convenient. A second Owner confirms live, the security channel is posted within 5 seconds, the grant expires in 60 minutes, and the mandatory review item blocks the next accounting period close until it is signed off. pa_0405 is that item.

Four-eyes queue

The single place every second approval happens, so that "requires approval" is a control rather than an email thread. Credit adjustments, refunds, lifecycle transitions, rate card publication, goodwill credits and availability determinations all arrive here, ordered by expiry.

Open requests
9
You may act on
6 as r.lee
Blocked by policy
3 conflict
Oldest waiting
4d
Value at risk
S$25,498.80
Expiring < 6h
1 impersonation

Pending approvals

Ordered by expiryActing as r.lee · Finance Controller
RequestTypeRequesterSubjectValue at riskExpiresPolicyAction
APR-1188Impersonationa.wongMeridian Capital Advisors high sensitivityContent access22mread_content on a high-sensitivity tenantNot your authority
APR-1184Cash refundk.ongRidgeway Legal LLPS$1,240.0041hRefund above S$500 requires a distinct second approver
APR-1185Goodwill creditk.ongMeridian Capital Advisors · ADJ-0243S$31.00 3,100 cr47hDay's goodwill total exceeds the ceiling
APR-1186Goodwill creditk.ongRidgeway Legal LLP · ADJ-0244S$22.00 2,200 cr47hDay's goodwill total exceeds the ceiling
APR-1181Credit debitr.leeKallang Trading · ADJ-0250 clawbackS$34.40 4,000 cr44hEvery manual debit is four-eyes, without thresholdYou raised this
APR-1179Lifecyclek.ongHarbourfront Legal · restricted → suspendedS$18,400.004dCommercial suspension of an enterprise account
APR-1176Rate cardk.ongPublish rate card v5+3.4pt blended · 31 tenants6dRate card publication is two-person (FR-CRD-019)
APR-1174Flag GAs.tanbyok_shadow_metering → general34 tenants exposed3dGA promotion is two-person (FR-PLT-012)Not your authority
APR-1191Availabilitys.tanCorrect published attainment · Jan 2026 · 99.84% → 99.48%S$5,771.406dA departure from the computed schedule routes whatever its value

Decision · APR-1184 · cash refund

S$1,240.0041h remaining
Requested by
k.ong · Billing Operator
Requested at
15 Aug 08:32
Tenant
Ridgeway Legal LLP
Reason code
correction_of_error
Evidence
SUP-1187 · INV-2026-0436
Refund against
INV-2026-0436 subscription
Lot refundable
Yes · purchased
Cash out
S$1,240.00
Credits reversed
0 cash line, no lot
Tenant lifetime billed
S$26,840.00
Requester's justification
Ridgeway Legal were billed a full month of Professional subscription on
INV-2026-0436 covering 13–31 Aug, but their seat count was reduced from 50
to 38 effective 01 Aug under the amendment signed 28 Jul. Twelve seats at
S$103.33 for the period = S$1,240.00 overcharged. Customer noticed, not us.
Refund to the original card rather than credits, at their request.
Precedent. Two prior refunds to this tenant, both billing corrections, both approved. Average time to decision 4h. No pattern of disputed charges.
Why cash and not credits. Goodwill is issued as non-refundable credits with contra-revenue treatment. This is not goodwill — it is money taken in error, so it goes back as money. Conflating the two is how a billing error becomes a customer-relations problem.

Why three are blocked

Policy
SELF
APR-1181 · you raised it
Self-approval is structurally impossible: the approve control is not rendered for the requester, and the API rejects it independently.
SOD
APR-1188 · impersonation
Finance Controller holds no impersonation authority and cannot approve it either. Nobody who moves money may see customer data.
SOD
APR-1174 · flag GA
Platform rollout approvals sit with Platform Engineering and the Owners. Finance has no infrastructure authority.
A blocked approval is shown with its reason rather than hidden. Hiding it teaches operators that the queue is unreliable; explaining it teaches them the separation-of-duties model, which is the same thing an auditor wants to see written down.

Expiry, not escalation

Raised Pending Approved
Raised Pending Expired must be re-raised
Requests expire rather than lingering: 48h for financial items, 7 days for rate cards, lifecycle, availability determinations and flag promotions, minutes for impersonation. An expired request cannot be revived, which prevents a stale approval being harvested weeks later against a situation that has changed.

One determination, not fourteen approvals

FR-BIL-019
The judgement sits in the month, not in the tenant. When a monthly availability commitment is missed, the determination is authorised once for the whole affected population — recording the measured attainment, the tier each tenant falls in and the total to be credited as the value at risk. Every individual credit then issues without further approval, because each amount is computed from a published figure and that tenant's own billed and metered volume. There is nothing per tenant left to weigh, and a queue of fourteen identical decisions would fill in precisely the month the same finance roles are handling the incident that filled it.
1
Accrual and invoice line
No second approver — authorised by the determination (FR-BIL-006)
Automatic
2
Departure from the computed schedule
Uplift, waiver, or a correction to a published figure — routed whatever its value
Four-eyes
3
Cash discharge on churn
A credit note, so four-eyes at any value under FR-BIL-006, and routed under FR-CRD-019 above S$500
Four-eyes
APR-1191 crosses a tier boundary, which is why it is here. A probe audit found January's maintenance window double-counted; corrected, attainment falls from 99.84% to 99.48% and moves every affected tenant from the 10% band to the 25% band. Total credited rises from S$3,847.60 to S$9,619.00, and the S$5,771.40 difference is the value at risk. Approving it republishes the figure and re-runs the determination — including for Novena Partners, who have already left and would be owed a further S$81.00 in cash, because this instrument does not expire and does not stop mattering when a tenant does.

Decisions · last 30 days

64 closed
OutcomeCountMedian time
Approved512h 41m
Declined61h 08m
More evidence requested43h 22m
Expired unactioned3
Three expired unactioned in 30 days. Each one was re-raised and approved later, which means the control worked but the queue was slow. Median time to decision is the number to watch: an approval queue nobody clears becomes an approval queue everybody routes around.

Operator roles & separation of duties

One role holding every power is not defensible to a regulated buyer, so the platform administrator is decomposed into nine. This is the matrix a procurement team asks for, rendered as an operating control rather than a policy document.

Roles
9
23 memberships across 21 people
Conflict rules
5
Declarative, enforced at grant time
Violations
1
Blocking · resolve before next close
Attestation due
30 Sep
Q3 campaign · 4 memberships unattested
Four-eyes capabilities
14
Of 31 in the matrix

Separation of duties matrix

Y permittedY* four-eyesR read onlyQ may request— denied
CapabilityOwnerPlat EngSupportCSMAEBillingFinanceCat GovSec & Comp
View tenant directory & healthYRRRRRRRR
Provision trial tenantYYY
Provision paid production tenantY*QQY*Y*
Suspend tenant (commercial)YQY*Y*
Suspend tenant (security / abuse)YYQY
Schedule tenant deletionY*Y*Y*
Grant credits against confirmed paymentYYY
Goodwill grant ≤ 2,000 creditsYYYYY
Goodwill grant 2,001–50,000Y*QQY*Y
Manual credit debit (clawback)Y*QY*
Cash refund > S$500Y*QY*
Publish rate card versionY*Y*
Impersonate tenant user (standard)Y*YY*
Impersonate into high-sensitivity tenantY*Y*
View tenant content (artefacts, evidence)Y*Y*Y*
Cross-tenant audit searchYRY
Review privileged-access logYY
Feature flag: general availabilityY*Y*
Declare / resolve incidentYYYY
Act on production estateYYYYRYYYR
Changing any cell in this grid is itself a four-eyes action and produces a before/after diff in the operator audit trail. The matrix is data, not code, so a control change is reviewable by someone who does not read code.

Roles and membership

21 people
RoleMembersNamed here
Operator Owner2m.chan · p.nair
Platform Engineer4s.tan +3
Support Engineer6j.lim · a.wong +4
Customer Success Manager3c.yeo +2
Account Executive2b.ho +1
Billing Operator2k.ong +1
Finance Controller1r.lee
Catalogue Governor2l.foo +1
Platform Security Reviewer1d.rahman
Finance Controller has one member. Only two identities hold authority over money at all — k.ong as Billing Operator and r.lee as Finance Controller — and neither may approve their own request, so every four-eyes money item needs the other one and a single day of leave stalls the queue. Goodwill above 50,000 credits needs r.lee specifically, that being the one place FR-CRD-019 names a role rather than a count. Either a second Controller or a named Owner deputy is required before this is a real control rather than a bottleneck.

Conflict rules

1 violation
1
No principal may hold both a money-moving role and an impersonation-capable role
Checked across 23 memberships
0
2
No principal may hold Security & Compliance with any other role
The reviewer must be powerless over what they review
0
3
The approver must not be the requester
4 self-approval attempts rejected in 90 days
0
4
Financial approvers must not share a reporting line
k.ong and r.lee both report to m.chan · affects goodwill approvals above the ceiling
1
5
Operator Owner actions always require a second Owner
2 Owners in post; break-glass posts to security within 5s
0
Violation of rule 4 blocks until resolved. With one Finance Controller and one Billing Operator under the same Owner, the reporting-line test cannot pass for goodwill approvals above the ceiling. Two lawful resolutions: appoint a second Finance Controller outside that line, or route affected approvals to the second Owner. Until one is chosen, ADJ-0243 and ADJ-0244 sit in the queue.

Effective permission explainer

J. Lim cannot issue a refund. Support Engineer grants no refund capability, and J. Lim holds no other role. The nearest capability held is a goodwill grant up to 2,000 credits (S$20.00), which is a credit issue and not a cash payment. To make this possible somebody would have to add her to Billing Operator, which rule 1 would then block because she holds impersonation.
Q3 access review. Every membership is re-attested by an Operator Owner each quarter; unattested memberships expire rather than persisting. Four are outstanding, all Support Engineer, due 30 September.
← Register