Lesson publishing.
A deployed publishing system for a financial-education library. The build recomputes every figure an author declares and refuses to produce a lesson whose arithmetic does not hold.
Deployed system — this configuration is running in production. Client identities are withheld.
Classified as a system: an arrangement of automations, capabilities and human judgment responsible for an outcome. The outcome belongs to the arrangement, not to any one component in it.
No model anywhere in this entry. It is deterministic end to end — the behaviour comes from rules, arithmetic and explicit boundaries.
Objective
Let an author write lessons freely while making it structurally impossible to publish a wrong number, and keep publication itself a deliberate human act.
Runtime
01
Author
A lesson manifest declares slides, copy and the figures it claims.
02
Recompute
The engine derives every declared figure from first principles.
03
Refuse
A declared result that disagrees with the computed one fails the build outright.
04
Review
Passing lessons produce reviewable artifacts, still unpublished.
05
Publish
An author marks the manifest published; drafts never reach the live library.
Anatomy
Context
- Lesson manifests as source of truth
- A locked curriculum architecture
- Declared figures and their inputs
- Approved cover assets
Capabilities
- Recompute compound growth and contributions
- Recompute loss-recovery thresholds
- Validate structure against the curriculum
- Generate decks, captions and lesson pages
- Synchronise the library index
Activation
- Author runs validate or build
- Deploy after an explicit publish mark
Authority
What can it change?
- Autonomy
- Assist
- Horizon
- Author-invoked
Read
- Lesson manifests
- Curriculum architecture
- Cover assets
Write
- Generated lesson pages
- Build artifacts for review
- The library index
Conditional
- Publish a lesson only once its manifest is deliberately marked published and its approved cover exists
Prohibited
- Build a lesson whose declared arithmetic disagrees with the engine
- Surface a draft on either live library
- Move or rename a live lesson route ad hoc
Escalate
- Declared figure outside tolerance — the build stops
- Missing approved cover
- Structure conflicting with the locked curriculum
Composition and verification
Made from explicit parts.
Composition
- Manifest-driven lesson engine
- Deterministic financial computation
- Build-time correctness gate
- Reviewable artifacts
- Human publish step
Verification
- Every declared figure recomputed from first principles
- Explicit tolerances — 0.05% on rates, 0.51 on currency
- Build fails closed on any mismatch
- Engine unit tests run separately from content validation
- Publication requires a deliberate manifest change
Evidence
Check it yourself.
An author's declared figure is never taken on trust: the engine recomputes it and refuses to build when the two disagree.
A mechanism, shown in source
function assertExpected(calculation, field, actual, label = field) {
if (calculation[field] !== undefined && Math.abs(actual - Number(calculation[field])) > 0.51) {
throw new Error(`${calculation.id} expected ${label} ${calculation[field]} but computes to ${actual}`);
}
}The tolerance is 0.51 on currency and 0.05% on rates — wide enough to absorb rounding, narrow enough that a real error cannot pass. Declaring a 50% loss needs a 60% gain to recover is rejected: the engine computes 100% and throws. Declaring a value 40 cents out is accepted as rounding; two euros out is not.
- Declared figures recomputed
- 22
- grep -c ' assertExpected(calculation' core.mjs
- Financial models covered
- 14
- grep -c 'calculation.type === "' core.mjs
- Engine tests
- 15 passing
- node --test core.test.mjs
A financial-education library. The engine is published here; the lessons it builds are the client's and are not. No figure above comes from lesson content — each counts a mechanism in the code.
What this establishes: that the mechanism exists and behaves as described, in source you can read and by figures you can reproduce. It does not by itself show the mechanism operating in production, and it is not an outcome observed by anyone other than us.
Next step
What you can do with this.
This configuration runs in production, client identity withheld. To discuss the same for your operation, start with the problem rather than the system: a first call is thirty minutes and costs nothing.
Related entries