GIPR Core · Context layer · In beta

Two of your systems disagree. Your report doesn’t.

One value wins. The other one never reaches the number.

Accounts payable, the card program and the department’s own report can each hold a different value for the same supplier. GIPR Core keeps every version. The disagreement is recorded as a fact of its own — not a ticket that closes when someone picks a winner — and the rule that ranks the sources is one you wrote, in your own terms, dated and versioned. Where no rule ranks them, the record says so. Every finding that rests on a contested value says so, all the way to the number on the page. Nothing is written back into your systems: Core surfaces and records; your people decide.

Deploys without touching your ERP — no install or integration project needed to get value 130+ entity types, generated from the deployed schema Every rule that cannot run says why — never a zero that looks clean · patent-pending
One bill, two channels · illustrative Same supplier, same amount
Fig. 01 — Neither side sees across
The same bill, paid twice, two days apart
Field Accounts payable Card program
SUPPLIERBluestone Facilities ServicesBluestone Facilities Services
AMOUNT$4,850.00$4,850.00
DATE21 April23 April
UNITFacilities · North siteIT · South site
CHANNELVoucherPurchasing card, no PO
Found only when
both halves are read
$4,850.00

One bill, paid twice — once by voucher, once by card. Each unit’s own review saw one half and nothing unusual in it — which is why the finding attributes at the organization level rather than to either unit. Illustrative figures from a synthetic dataset.

The context layer for source-to-pay 130+ entity types Append-only provenance record Offline verification

01 — What a context layer has to hold

Meaning. Relationships. And a record of what happened.

Semantic layers settled what your words mean. Knowledge graphs settled how your things relate. Both are solved markets with capable incumbents. GIPR builds on the third part — a running record of the events, decisions and actions behind a number — because that is what decides whether an agent can act on your data or only describe it.

Meaning Ships pre-built

The ontology

Suppliers, contracts, requisitions, purchase orders, receipts, invoices, payments, encumbrances and approvals — modeled, constrained and provenance-tracked on day one. You argue with it and adjust; you don't start from a blank page.

Relationships Typed, constrained

The graph

What kinds of things exist and what is permitted between them — the grammar of a procurement operation, enforced by uniqueness constraints in the deployed schema rather than by convention.

Record The running record

The provenance log

Every assertion written once to an append-only, content-hash-gated log and never edited. The data, the policy version and the source ranking in force at the moment a decision relied on it — independent of whichever model or person acted.

02 — How it works

Both values survive. A rule you wrote decides.

Anywhere two systems meet — an integration job, a monthly reconciliation, an analyst’s judgement call in a spreadsheet — one value is kept and the other is written over. That is what joining data is for, and for most purposes it is the right trade: the job of that layer is to produce one number. The cost is that the choice itself leaves no trace, so a report inherits it without being told a choice was made, and explaining why a number came out the way it did becomes archaeology. Adjudication in Core is non-destructive by construction — nothing is overwritten, so nothing has to be reconstructed later.

01

The losing value is still there.

Every assertion is written once to an append-only, content-hash-gated log and never edited. The value that lost an adjudication is retained beside the one that won, with the source that asserted it. The graph you query is a projection of that log — the log is the record, not the database.

Warehouses do retain history — slowly changing dimensions, data vault, a raw landing layer, time travel. What none of them record is which of your written rules decided a given field, and none of them carry that contest onto the finding computed from it. Retention is not the distinction. The decision, and where it travels, is.

02

You author the rule that decides.

Which source outranks which, for which field, is a rule you write and amend. The rule that decided a field is linked to the field, so “why is this the number?” has an answer you can read. Rule changes go through the same append-only log, so the ranking in force on a given date is replayable rather than remembered — we can show which version governed a decision and re-derive it under that version. That replays the rule, not the underlying data as it stood at the time.

When no rule matched, the record says so — rather than quietly picking one and presenting the result as settled.

03

The contest is not left behind at the record.

It arrives with the report, with the export, and with the answer a machine reader gets back. The disagreement does not stay behind in a data-quality console that nobody in finance opens.

04

Three signals, never blended.

Fidelity — is the record well-formed and complete. Veracity — do the sources that describe it agree. Authority — did a rule you wrote decide this field, or did nothing decide it. Each is reported on its own, with a band, and there is no fourth number that combines them.

They mean corroboration and conflict. They do not mean “is this true.” A high score is not a fact-check and we will not sell it as one.

05

Nothing in your systems of record is altered.

Core performs no write into any source system. It produces findings, an evidence record and a verdict; what your systems do with that verdict is your decision. We compute; you decide.

03 — What it produces

A diagnostic that runs itself, and shows its work.

Every ingest runs a 19-rule diagnostic pack across your spend graph — no question asked, no analyst driving it. What comes back is three separate numbers that are never blended, and a method string on every row that a person can recompute by hand.

Found Summed

Found dollars

A specific transaction, a specific amount, a specific reason, and the records on both sides — so your team can go and check it. The only number we sum.

Exposed Listed, never summed

Exposure indicators

Dollars sitting where a control did not hold. Every one listed with its amount and never added into a headline — a test in our build fails if one ever is.

Modeled Shown as a band

Addressable ranges

Ranges, with overlaps flagged so you can see where two opportunities are the same opportunity counted twice. Always a band.

And it tells you what it could not check. Rules that cannot run on your data stay locked and say why in plain language — each naming the specific coverage, volume or field it needed. A rule that could not run returns a stated reason rather than a zero that looks like a clean result. The same report lists what would unlock further analysis.

04 — Getting it running

Nothing to install. Send a file, or point us at a feed.

Getting this view usually means a data-warehouse project — an integration budget, a build, and a queue at the BI team. Core does not need one. It reads what your systems already export.

01

Send a file

Spreadsheet and CSV extracts, single files or zipped bundles, placed by a person or by a scheduled export you already run. No install, no API credentials and no integration project needed to get value, and no agent on your network. If you later want findings pushed into a system of record, that is integration work GIPR Connect does.

02

Confirm the mapping once

High-confidence columns map themselves; everything else a person confirms one time. After that, scheduled drops into your folder run end to end unattended, with recognized layouts routed automatically.

03

Every arrival is attested

Whichever way the data arrived, the moment it crossed the ingestion boundary it became a content-hashed, logged, per-source-attested observation. Your auditor can verify that record offline — one script, no database, no network, no trust in us.

04

Built for real volumes

A two-million-row load runs end to end in well under an hour on modest hardware, and we size the run to your data before we start rather than after. If volume is your question, ask and we will show you the measurement.

05 — Where Core stands

In beta. Stated as such.

Core is the newer of our two working products and we describe it precisely, because a security reviewer will ask and a feature list that blends what runs with what we intend is how vendors lose that conversation.

● RUNNING TODAY

The ontology, the append-only provenance record, offline verification, the three signals, client-authored authority rules, the 19-rule diagnostic with honest bands, and the disclosure of what could not be checked.

◐ STATED PRECISELY

The three signals are computed and surfaced. They are not enforced — they do not stop a transaction, and we do not claim they do. Core surfaces and records; your people decide.

Ask us to run any row →

Next — Talk to us

Bring us two systems that disagree.

That is the demonstration worth having, and it is the one we most want to run on real data.

Scope an assessment

Or request an analyst briefing →