Each rule below is enforced structurally in the codebase, which is the only reason it is credible to say out loud. Read them as the contract every figure Assay prints is held to — including the figures on this site.
01
Unknown is not zero
If the pricer cannot vouch for a model, the span records its tokens and no cost — deliberately diverging from the upstream SDK, which falls back to $0. A false $0.00 under-reports spend; an absent cost is the truth.
45,255
of 253,417 spans carry no price, by design — excluded from every total, and every total says so. Measured 2026-08-03.
$0.00 is a claim.
“Unpriced” is a fact. An unpriced span is a model Assay cannot vouch for, not a free one.
02
A wrong figure is corrected, never rewritten
A price change never reaches back. When a figure is knowably wrong the remedy is an append-only correction row that every read resolves, carrying its own version and what it replaced. Unknown stays unknown: a model the table still cannot vouch for gets no correction row, and nothing is ever estimated from a corpus-wide average.
86,235
append-only correction rows on our own store, all stamped assay@6, recovering $5,575.91 — with every original figure still intact beside its correction.
0
edited rows. A span is written once; the storage port exposes no update and no delete.
Every console page closes with where its numbers came from — the correction policy, the unpriced population, and the pricing version they were priced against.
03
A measured zero is never folded into an unknown
This cost nothing and we cannot measure this are different facts. On the live store the two residual populations in product attribution are $22.08 and $13,083.91 — the unknown is 593 times the zero. Merging them would have stated 30% of the ledger as a fact.
$22.08
measured zero — those sessions were read and referenced no workspace at all. That is a finding, and it stays in every denominator.
$13,083.91
genuinely unknown — no source document was available for them. Excluded, counted, and printed beside the ratio it is excluded from.
04
Two readings, both named
Where a question has two honest answers, Assay prints both and labels which is which: inclusive, an upper bound that deliberately does not partition, and weighted, an estimate that does. It never picks one silently.
Inclusive
the whole spend of every session that touched the product. A session that touched three products is counted whole in all three, so the column sums to more than the window total.
Weighted
each session's spend times its share of that session's workspace references. Summed over 213 products it comes to $30,795.52 — exactly the covered population, to 123 µUSD of symmetric rounding.
05
Every ratio surfaces its exclusion
Waste, cost-per-outcome, token yield and ROI all compute over priced spans only, and each carries the count and share it excluded. Every share divides by the whole window's spend, never by what the page happens to show.
The console says it on the page, next to the bars — not in a footnote and not in the documentation.
06
A zero is rendered with its reason
A detector that fires with $0.00 recoverable, a token yield of 0%, a cost-per-outcome of $0 — each is a result conditioned on something, and the surface says what.
Dollar ROI is undefined on our own live store, and it says so. All 932 outcomes are automatic; zero carry a declared dollar value. So the panel reports the ratio as null with the reason stated, rather than printing the arithmetic (0 − cost) ÷ cost = −100%, which is arithmetic wearing the clothes of a measurement.
07
A stale number is the same class of error as an uncorrected one
Every static snapshot page carries a fidelity stamp — capture instant in absolute UTC, store, version, window, filters — ending in these numbers do not update.
Site copy follows the same rule. Every figure on this site carries the date it was measured, because an undated number drifts and a rounded one hides. If a claim cannot carry a real number, it is stated mechanically instead.
The other half
The bounds that ride with every claim
The brand is that these are stated. Each one is a real limit on a real capability, published on the same page as the capability it limits.
Invoice reconciliation covers API-key traffic only. Subscription usage has no invoice to reconcile against, so a subscription-heavy store shows a large negative drift — and that is a correct result. The verb says so in its own output.
The closed vocabulary fixed aggregation, not per-session accuracy. On a 7B local judge, 13.7% of answers land on the escape label, and at least 32 of those 135 literally say the context does not say. The remedy is a larger local model; the sovereignty rule constrains where the model runs, not how big it is.
Dollar ROI is undefined on our live store. All 932 outcomes are automatic; zero carry a declared dollar value. The ratio is reported as null with the reason, not as a number derived from a zero.
Interactive work has no outcome source. Outcomes arrive from automated beats. A human-driven session produces spend, a transcript and a goal label — but no outcome, so it sits outside every cost-per-outcome ratio. The bound population is small: 309 outcomes bound to $335.64 of a $45k ledger, 2026-08-02.
78,582 spans keep an understated cache-write cost permanently. Their source logs are gone, so the correction pass cannot observe the real cache TTL. Estimating them from corpus averages is exactly what the design refuses to do.
Erasure is immediate in the live store and irreversible only after backups rotate — no more than 35 days in our deployment, because the master key is inside the backup set by design. Quote the window, not the exit code.
A reference is attention, not authorship. Product attribution measures which workspaces a session referred to. It is evidence, honestly bounded, not a claim about who wrote what.
Value is user-supplied — here as everywhere. Assay does not differentiate on measuring value better. It differentiates on the substrate: event-sourced, sovereign, local-first, span-grained, and transcript-joined.
The repository is private today. The MIT grant on the substrate is standing, so publication would be a visibility flip rather than a relicensing — but it has not happened.
Bounds measured 2026-08-02 and 2026-08-03 · these numbers do not update
We publish what it cost us to find our own mistakes.
Nine dated proof points from our own store — including a dashboard of ours that under-reported by 13.1%, and the fence that now catches it.