The place where the organisation decides what is true, what is connected, and what happens next.
01 · DefinitionWhat it is
KXCO Ontology is the operational layer that turns fragmented institutional data and public records into a living, decision-ready structure. It does three things continuously:
- Resolves entities and relationships into a typed, time-aware graph.
- Records human judgment, confidence and provenance as first-class data.
- Makes every consequential change previewable, auditable, and optionally anchorable to a public ledger under a quantum-resistant institutional identity.
It is not a data catalogue. It is not a semantic layer sitting on top of tables. It is the place where the organisation decides what is true, what is connected, and what happens next.
Two things make that possible, and neither of them is a model. The first is data you can attest to. The second is people who know what it means. The rest of this post is about why those two, held in one structure, produce a result that neither more data nor a bigger model can reach on its own.
02 · ValueWhy attested data sets the ceiling
The value an institution gets from AI is capped by what the AI is answering from.
Hand a model an estate of contradictory spreadsheets, slide decks, PDFs and inboxes and it will return fluent prose. Fluency is not the problem. The problem is that the confidence of the writing carries no information about whether the content is right, and nobody reading it downstream can tell the difference.
Hallucination is usually described as a model defect. Inside an institution it is more often a data defect. A model asked a precise question about a precise counterparty, with nothing in front of it that actually states the answer, has two options. Guess, or decline. Most guess, because a guess satisfies the request. Remove the need to guess and most of the guessing stops.
That is what attestation does. In KXCO Ontology every value arrives with four things attached: who asserted it, from what source, as of when, and with what confidence. An assertion without those is not a weaker claim, it is not a claim at all, and it does not survive entry. Where the record holds no answer, the absence is a typed state the system displays rather than a blank waiting to be filled.
The public demonstration graph marks a cell as unwired, not yet reported, or not applicable rather than estimating it. A figure nobody has filed stays visibly unfiled. This is the most useful discipline in the system and the one most often skipped elsewhere, because an estimate looks more finished than an honest gap.
Two consequences follow, and together they are the whole argument for doing the structural work.
- The model stops being the source of truth. It reads, extracts, proposes, retrieves and drafts across a bounded body of attested claims. What it cannot do is originate a fact, because there is no way into the record that does not carry a source.
- Every answer can be walked back. A number in a briefing note resolves to a claim, which resolves to a source, a date, a confidence and the person who accepted it. Checking the answer takes seconds rather than a week, which is the difference between an assistant you can use in a regulated process and one you cannot.
A larger model over a fragmented estate returns a more fluent version of the same uncertainty. The ceiling moves when the substrate changes, not when the parameter count does.
03 · ModelCore primitives
| Primitive | Purpose |
|---|---|
| Object Types | The nouns of the institution: Person, Organization, Asset, Location, Event, Claim. |
| Objects | Named instances of those types. |
| Link Types | Directed, typed relationships with temporal bounds. |
| Properties | Attributes that can themselves carry validity windows. |
| Action Types | The kinetic layer: parameterised operations that change the ontology under explicit preconditions. |
| Observations | Human or machine assertions that enter with confidence, source and temporal scope. |
| Ledger | Append-only, hash-linked record of every material change. |
Every claim carries confidence, provenance (who, when, role, source), valid-from and valid-to, and a recording timestamp. These four dimensions travel with the data. They are never optional metadata.
04 · ResolutionExtraction and human resolution
Machine extraction proposes. Humans decide.
The system surfaces candidate entities, possible merges and typed relationships. Analysts accept, correct, reject or add context. Every human decision is recorded with the same rigour as the original claim.
Entity resolution is case-insensitive and confirmation-gated. “Acme Corp”, “ACME CORP” and “acme corp” resolve to one object unless the operator deliberately creates a second.
This is deliberate. Volume is cheap. Correct structure is expensive. The ontology optimises for the latter.
The audit trail is therefore symmetrical. A machine extraction and an analyst's correction of it are the same kind of object, carrying the same four dimensions, open to the same inspection and the same later dispute. Nothing in the record is privileged because of where it came from.
05 · JudgmentWhere skilled people add context
Mining gets you breadth. It does not get you meaning.
Machine extraction is fast, tireless and comprehensive. Every filing, every register, every disclosure, every price file, read again whenever any of them changes. No team can match that reach and no team should try to.
Four judgments stay stubbornly human.
- Which entity is the one that matters. Six companies share a name across three registers. One of them is your counterparty. Nothing in the text says which.
- Why a relationship exists. Two names appear in the same document. The link is either a formality or the entire exposure, and the difference lives in someone's experience of that market.
- What a document is silent about. A filing that stops disclosing a segment it used to disclose has told you something. Extraction reads nothing there, because there is nothing there to read.
- Which source to believe. Two credible sources contradict each other. Choosing one is a judgment with consequences, and it should carry a name.
These are the moments where a trained analyst is worth more than another rack of accelerators. Someone who has covered a sector for a decade knows that a phrase in a prospectus changed this year, that a director's second board seat is the real connection, that a parent moved jurisdiction two quarters ago and the group chart still in circulation is stale.
An institution’s real asset is not its data. It is the judgment its people apply to that data, and almost none of that is written down anywhere a machine can reach.
Context as data, not as commentary
In ordinary software that judgment lands in a comment field, a slide, a mail thread, or nowhere. It cannot be queried, it is not dated, and when the analyst leaves it leaves with them.
Here it enters as an Observation. Typed, attributed to a named person in a named role, scoped to a period of validity, carrying a confidence and a source. The same object type a machine extraction produces. That one decision, treating expert context as first-class data rather than annotation, is what makes everything else compound.
- Judgment accumulates instead of evaporating. Ten analysts working for a year leave behind a structure, not a folder of documents.
- Disagreement survives. Two analysts can hold different confidences on the same claim. The graph shows both, dated and attributed, instead of averaging them into a number nobody stands behind.
- Reasoning is inheritable. A new joiner reads why a link was accepted, not only that it exists.
- Accountability has an address. Forward and rear analysts propose. Only an administrator approves and executes. Every step carries a name.
Volume is available to everyone now. Context is not, and it does not arrive by buying more data.
06 · CompoundHow it comes together
Four inputs. None of them is sufficient alone, and the value is in the combination rather than in any one of them.
| Input | What it contributes | What it cannot do |
|---|---|---|
| Mined data | Breadth. Everything on the record, continuously. | Decide what any of it means. |
| Expert context | Depth. Meaning, motive, and what the record leaves out. | Scale to millions of documents. |
| Typed structure | Comparability. Both kinds of input become the same shape, so they can be queried together. | Supply the judgment. |
| Time and provenance | Defensibility. Every claim stays tied to when it was true and who said so. | Make a claim correct. |
Put them in one structure and the sequence runs like this. Machines read at a scale no team can, and propose. People decide, and their reasoning is captured with the same rigour as the data. The graph renders the result as a shape rather than a paragraph. A person looks at the shape and recognises what it means. The ledger records what was decided, by whom, and when.
That last step matters more than it sounds. An ontology is an instrument, not an oracle. It does not hand down conclusions. It puts structure in front of human judgment in a form judgment can work on. The discovery is always the person's, and the system's contribution is making the insight reachable at all. Without a display in which the shape can be seen, nobody goes looking, and facts that have been public for years stay practically invisible.
Reading everything. Proposing candidates and merges. Answering questions over a bounded, attested body of claims. Drafting the note a person then checks. Flagging that a source has changed since a claim was accepted.
What it is not asked to be is the source of truth. That role belongs to the record, and the record is built by people using machines rather than by machines reporting on themselves.
This is what deep research looks like when it stops being a document. Breadth from mining, depth from people, structure so the two are comparable, time so both stay honest, provenance so any line can be walked back to source. The output is not a smarter answer. It is an answer whose basis you can inspect, and a wrong answer you can find the cause of.
07 · KineticThe kinetic layer
Actions are not buttons. They are first-class ontology objects.
An Action Type declares which object types it applies to, its required and optional parameters and their types, preconditions expressed over the current state of the target, and the exact ontology effects that will be applied on execution: attribute changes, link withdrawals and additions, note attachments.
Before any irreversible step, the operator sees a predicted diff. The same computeDiff function that generates the preview is the function that later executes. There is no second code path.
Execution is the only transition that is anchor-worthy. Proposals and approvals produce ledger entries; only Executed changes the world and, by policy, triggers anchoring.
Role gating is enforced. Forward and Rear analysts propose; only Admin can approve and execute.
08 · TemporalTime
The ontology is bi-temporal.
- Valid time. When the claim was true in the world.
- Transaction time. When it was recorded in the system.
A time scrubber lets any operator view the ontology as it existed at a chosen point. Assertions outside the validity window disappear. Attributes rewind through the ledger. Observations after the scrub point are dimmed and labelled. Writing is blocked while the view is historical.
Undated assertions remain visible and are explicitly badged. The system refuses to invent commencement dates.
09 · SurfacesVisibility and interrogation
The primary surfaces are:
- Graph. Type-coloured nodes, confidence-weighted edges, selection focus, path highlight, scrubber filtering.
- Inspector. Full attribute, connection, provenance and confidence detail for any selected object, with the Actions available against it.
- Command Palette. Ctrl or Cmd-K for fuzzy access to objects, Action Types, observations and ledger entries.
- Path Finding. Shortest path or paths between any two objects, with weakest-link confidence and graph highlight.
- Ledger view. Every material change with its hash chain status: Local only, Anchored, or Broken chain.
Broken chain dominates. An entry that was previously verified stops displaying as Anchored the moment the chain beneath it no longer recomputes.
10 · IntegrityAccuracy and integrity
Contradictions are refused at the point of entry with an explanation. The ledger is hash-linked, so any alteration or reordering is detectable.
Anchoring is selective and disciplined. Only Executed actions and schema changes auto-anchor. The log head can be anchored on demand as an audit root. The system refuses to anchor a broken chain.
Anchors are written to Armature L1 using ML-DSA-65 (FIPS 204). They prove the existence and timestamp of a digest under the institutional KXCO identity. They do not claim to prove the underlying truth of the observation.
Signature verification occurs off-chain at the relay. The client never holds private key material. Verification is performed directly against the public RPC; no intermediate attestation service is required for relay-anchored digests.
11 · UseRisk, opportunity, understanding
Everything above exists to make three ordinary jobs possible. This is the part a board cares about.
Monitoring risk
Exposure is a path problem, not a field in a table. The concentration that hurts an institution is rarely in the first hop. It is the third supplier shared by four positions, the parent two levels above a counterparty, the one person sitting on three boards inside the same portfolio.
- Exposure recomputes. Links are typed and traversable, so when a claim changes, everything standing on it can be recalculated rather than re-researched.
- Weakest-link confidence. Path finding reports the confidence of the shakiest assertion on the route, so you know how much of a conclusion rests on your least reliable input. Most reporting systems cannot produce that number at all.
- What did we know, and when. Bi-temporal reconstruction answers the question that actually gets asked after an incident, in front of a regulator or a court, and answers it from the record rather than from memory.
- Opacity is itself a report. You can see which parts of your exposure you cannot see. A named gap is manageable. An estimate dressed as a fact is not.
- Tampering shows. The ledger is hash-linked, so a quietly edited history stops verifying. A broken chain is displayed as broken and cannot be anchored.
Spotting opportunity
Opportunity in a structure is usually a mismatch. A dependency priced as though it were replaceable. A relationship that repeats across names the market treats as unconnected. A supplier that turns out to sit underneath three positions you thought were diversified. A capital flow that leaves and returns to the same balance sheet by a different route.
None of that is hidden. It is almost always in public filings, and it has usually been there for years. What is missing is a rendering in which the shape can be seen at all, and that is the gap the ontology closes. The engine lays the structure out. The person reading it recognises what it means, and the recognition is the valuable part.
The practical form this takes is a gap between two things: what the record supports, and what the market appears to assume. Both sides of that comparison need to be attested before the gap means anything, which is why the discipline in the earlier sections is not academic.
Understanding
The least glamorous benefit is the one people notice first.
- Arguments move on. A committee stops arguing about whose spreadsheet is right, because there is one resolved entity and one dated claim, and the argument becomes about the claim itself.
- New people get productive faster. A joiner reads the structure and its provenance instead of absorbing institutional folklore over two years.
- Research stops expiring. A research document is a snapshot that decays from the day it is filed. A structure is a state that gets amended, with the previous view still reconstructible.
- Briefings become reproducible. Anyone can regenerate the note and get the same answer, or see exactly which claim changed and made it different.
| What you get | What makes it possible |
|---|---|
| Exposure that recomputes | Typed, traversable links rather than joined tables. |
| Answers with a basis | Provenance and confidence travel with every claim. |
| A defensible history | Bi-temporal reconstruction plus a hash-linked ledger. |
| AI you can put in a regulated process | The model answers from attested claims and names its gaps. |
| Judgment that accumulates | Human observations are data, not comments. |
| Fewer arguments about numbers | One resolved entity, one dated claim, one visible source. |
| Proof to a third party | Selective anchoring to Armature L1 under an ML-DSA-65 identity. |
12 · ApplicationWhere it applies
| Domain | Structural questions it answers |
|---|---|
| Banking and markets | Counterparty exposure, beneficial ownership chains, concentration risk. |
| Insurance | Accumulation, related-party networks, claim lineage. |
| Funds and private capital | Portfolio company relationships, key-person exposure, side-letter obligations. |
| Law and compliance | Conflicts, entity resolution across matters, privilege boundaries. |
| Operations and supply | Asset ownership, location history, quarantine and relocation workflows. |
| Intelligence and investigations | Entity resolution, temporal reconstruction, provenance of every assertion. |
The same primitives serve all of them. The ontology does not care which industry owns the data.
13 · StanceDesign stance
- Context over volume.
- Human judgment as a first-class input, not a cost centre.
- Preview before commit.
- Time as a first-class dimension.
- Provenance and confidence as non-optional.
- No optimistic status indicators.
- No invented commencement dates.
- The device is the boundary for local data; the service is the boundary for anything the service performs.
The system is deliberately conservative about what it claims.
Some of what it does not do is worth stating plainly. It does not predict. It does not score entities. It does not decide anything on its own, and it will not fill a gap in order to look complete. It cannot make an unreliable source reliable. Anchoring proves that a digest existed at a point in time under a known institutional identity, and nothing more than that.
14 · QuestionsCommon questions
Does an ontology stop AI hallucinating?
It removes the need to guess on any question the record covers, and that is where most institutional hallucination comes from. A model working over typed claims either finds the claim, or reports the gap as a gap, because an unfilled cell is a value in the schema rather than an empty space. It does not change how a language model generates text. Anything outside the attested record is still generation, and should still be read as generation.
What does attested actually mean here?
Four dimensions travel with every value: who asserted it, from what source, as of when, and with what confidence. Nothing enters the record without all four, and a human decision to accept, merge or reject carries them too. That is what makes an answer checkable by someone who was not in the room when it was produced.
If the machine reads everything, why do you still need skilled analysts?
Because four judgments are not in the text. Which of six similarly named entities is your counterparty. Whether a relationship is a formality or the whole exposure. What a document has stopped saying. Which of two contradicting sources to believe. Extraction proposes at a scale no team can match, and none of those four is a scale problem.
Can it tell me what to do?
No, and it is not built to. An ontology is an instrument rather than an oracle. It renders structure legible so that judgment has something to operate on, and the discovery stays the person's. What it does guarantee is that when a person decides, the decision is recorded, previewable before it commits, and reconstructible afterwards.
How is this different from a data catalogue or a semantic layer?
A catalogue tells you where data lives. A semantic layer renames columns so queries read better. Neither holds a claim with a source, a confidence and a validity window, neither records who decided what, and neither can execute a change to the world with a predicted diff shown first. The difference is not vocabulary, it is that this layer is where decisions happen.
What does anchoring to Armature L1 prove?
That a digest existed at a given time under the institutional KXCO identity, signed with ML-DSA-65 (FIPS 204). It does not assert that the observation inside the digest is true. Verification runs off-chain at the relay against the public RPC, and the client never holds private key material.
15 · NextNext
Live demonstration: kxco.ai/ontology-live
Machine-readable state: kxco.ai/ontology-live/data.json
Product overview: kxco.ai/ontology
Related reading:
- The end of the GPU arms race. Why the questions institutions need answered are structural rather than linguistic, and why compute does not substitute for context.
- How KXCO Ontology helps understand markets. The same sector read twice, first as a report and then as a graph, as a worked example.
- How to use the KXCO Ontology. A walkthrough of the public demonstration, surface by surface.
- Mapping data so people can understand it. Why the last bottleneck in the chain is human understanding rather than storage or processing.
For organisations whose structural questions cannot currently be answered cleanly across systems, request a briefing.