Separate the source, the review, and the decision.
Teranode Review is a deterministic control workflow around several model calls. Models surface attributed exceptions. Code enforces the boundaries. A person makes and records the final decision.
This page describes implemented behavior, not a claim that the review establishes correctness, independence in the assurance sense, legal sufficiency, compliance, or a best-interest determination under Advisers Act §206. Teranode's control is architectural separation from the submitted source, not a third-party attestation or assurance engagement.
The review begins with an identified source.
The operator identifies the recommendation as AI-generated or human-authored, supplies the original decision question, recommendation, and any relevant facts or constraints. An AI source includes its model vendor and model. A human source includes the originating team or role and is not assigned a model vendor. The operator must confirm that the submission contains no client-identifying information. A deterministic detection layer rejects obvious identifiers as a backstop.
The review can evaluate only the information supplied. Missing facts belong in findings, questions for the reviewer, or stated limitations, not in invented assumptions.
The submitted source remains distinct from the review.
For an AI-generated recommendation, routing excludes the source vendor before any reviewer is selected. For a human-authored recommendation, the originating team or role is recorded and no model vendor is attributed to it. In both paths, the four required lenses must complete across at least three distinct model vendors. The response schema independently checks the applicable separation rule and the vendor-diversity floor.
A malformed response, unavailable required lens, exhausted retry, or insufficient vendor diversity fails the review. Partial output is not presented as a successful review.
Four narrow assignments reduce role ambiguity.
Findings are flags, not determinations.
Every lens returns a strict structured response. A finding identifies the source excerpt, category, severity, factual gap, supporting evidence, contextual rule or policy, required human action, and whether human verification is required. Rules are context for the reviewer rather than the model's legal conclusion.
The prompts prohibit violation, breach, materiality, compliance, fiduciary, and best-interest determinations. The same restriction applies to each lens summary. Required actions use “Confirm” rather than “Verify” so the system does not imply that a check was already completed.
A suspected math error must be recomputed end to end from the supplied inputs, formula, units, period, convention, assumptions, and rounding. If that cannot be done rigorously, the lens abstains from a math-error finding and moves the uncertainty to reviewer questions or limitations.
No single AI makes the final call.
Required lenses run independently. Code validates and combines their outputs in a fixed order. Findings retain the producing lens, vendor, model, and policy version. No subsequent model votes on, rewrites, dismisses, or softens them.
Deterministic guards catch contradictory math-error findings and harden human-verification wording before the review is returned. A review with findings is marked “Exceptions to review”; a defect that should prevent use is marked “Material exceptions”; an empty finding set is marked “No exceptions.” Every state still requires human review before use.
Every finding must be dispositioned.
The reviewer marks action required, records that the answer addressed the finding, disagrees with the finding and supplies a written reason, or records that it does not apply. Any outcome other than Action required requires a reviewer-written reason. For Action required, the system records a standard concurrence on selection. The application requires exactly one disposition for every finding before attestation.
Final-decision states are constrained by those dispositions. A finding marked action required cannot produce an approved state, and a mitigated finding cannot produce an unchanged approval state.
The attestation is checked before the record is constructed.
The server validates the integrity token, source review, complete dispositions, reviewer fields, and final-decision consistency. It then constructs a canonical record containing the review, dispositions, reviewer, final decision, filing status, attestation timestamp, and SHA-256 content fingerprint.
The fingerprint allows two record contents to be compared. It is not an electronic signature, trusted timestamp authority, or authentication mechanism. It is not a tamper-proof seal. Filing occurs only when an authenticated firm archive exists; otherwise the record is explicitly marked not filed. Check a record.
The process score reports execution, not judgement.
Shared Council decision records carry a process score. It is deterministic and computed only from how the run executed: it starts at a value fixed by the depth selected, 0.90 for the Standard and Exam-Tested depths and 0.75 for Quick, subtracts 0.15 for each reasoner role that did not return, and subtracts a further 0.05 when the preserved objection runs past 300 characters. It never falls below 0.40, and it cannot exceed the starting value for its depth: a clean Standard run reports 0.90.
It is a completeness signal: which depth was selected, whether every reasoner returned, and whether a long objection was preserved. It is not a probability that the answer is correct, not a measure of agreement between reasoners, and not an assessment of the decision. A high score means the run completed at the depth selected. The Teranode Review record described above does not carry a process score; the reviewer's signed disposition stands on its own. Either way, the recommendation under review remains the firm's to evaluate.
Different vendors can still fail in the same way.
Cross-vendor routing reduces direct self-review, but it does not prove statistical independence. Models may share training data, retrieval sources, evaluation conventions, and common assumptions. Multiple reviewers may therefore repeat the same error.
The method does not establish that every relevant issue was found, that every finding is correct, or that the final decision satisfies any legal or professional standard. Provenance, questions, limitations, abstention, and human disposition are controls around that uncertainty, not a claim that it has been eliminated.
Open Teranode Review. Data handling is on Trust; application controls are on Security.
