Draft edition. Public Doctrine v1.2 — pending Founder review before this becomes the current published edition.
Human Heartbeat AI
Doctrine · Public edition

AI advises.A person decides.

That sentence is not a slogan. It is the governing rule underneath every system Human Heartbeat AI builds, and this is the doctrine that follows from it — published so it can be read, used, and argued with.

Where this comes from

Knowledge that lives somewhere you cannot look is knowledge you are about to lose.

I grew up in Blaenllechau, in the South Wales valleys, and I watched the coalfields go.

What people remember about that is the jobs. What I remember is what went with them. There were men who knew things — how a particular seam behaved, which way the water ran, what a certain noise meant and how long you had. None of it was written anywhere. It lived in people's heads, and it passed by standing next to someone.

When the pits closed, that didn't get archived. It just stopped.

So I have a lifelong distrust of knowledge that only exists somewhere you can't see it.

When I started building with AI, I recognised the same shape straight away. Something that holds information about your business which you cannot inspect, cannot correct, and cannot prove. I wasn't going to build that. Not after watching it happen once.

I am not a millennial from Silicon Valley and not a face on YouTube becoming an AI influencer. That is not modesty — it is the whole argument. The work has to stand up without the person, or it isn't work. It's a following.

The governing principle

The Human Decision Gate

AI is a decision-support intelligence layer.
Human judgement is the final gate.

Not because the technology is stupid — it plainly isn't. Because accountability doesn't distribute. When something goes wrong, a person answers for it. So a person should have authorised it.

Every other rule here follows from that one. A system can propose, draft, analyse, sort, calculate and recommend. It does not get to be the last thing that happened before the real world changed.

Which sounds obvious, and almost nothing is built this way. The gate gets skipped not by decision but by drift — a step automated here, a confirmation removed there, until the moment a person was meant to look has quietly closed up.

How the system stays honest with itself

Canon v Runtime

Runtime is what is actually running — what a system does in operation, live or in sandbox. It's reality, not intention.

Canon is the separate record of what is authorised to exist, and in what form. It's authority, not activity.

They are allowed to diverge. Runtime can run ahead of Canon — we call that momentum: the live pressure of building under real conditions, where halting until a formal record catches up would stop the work entirely. That is not a failure state. It's expected, and trying to prevent it produces slower systems, not safer ones.

What momentum carries with it is a duty, not a free pass. Divergence has to be noticed, brought back, and checked against the question that actually matters: does Canon still describe what's true, or has Runtime moved past it?

We call that check the Canon v Runtime alignment process. It doesn't assume either side is right. Sometimes Canon gets written up to match where Runtime has legitimately got to. Sometimes Runtime has drifted somewhere Canon was correct to guard against, and it pulls back. Either way, someone with the authority to decide — not the system that ran ahead — makes that call.

The failure isn't Runtime moving, and it isn't Canon lagging. The failure is the alignment check never happening — divergence left open, with nobody watching for it, until the gap has been live long enough that people start treating it as normal.

Wisdom Infrastructure · Ten cards

The spine

Ten reflexes, each one a collision between a word people treat as finished and the thing it was never evidence of. They exist because every one of them cost something to learn. Read the line first — then open a card for the reasoning and a worked example.

Card backs are draft. The reasoning is confirmed doctrine. The examples are generic illustrations, not real incidents — two of these ten cards were written against specific internal events, and per standing governance ruling that provenance is not published here. This expanded content awaits Founder review before the edition is finalised.
01
Visibleisn'tusable

A thing being on the screen is not proof that anyone can act on it.

Why this card existsHide
The reasoning

Being able to see a figure, a dashboard or a status doesn't mean anyone can act on it. Visibility still needs to be findable, understandable, and connected to something the viewer is actually allowed to do next. A screen is not a workflow.

In practice

A reporting dashboard shows the exact number a manager needs — three clicks deep in a tool nobody remembers the login for. The information exists. Nobody is using it.

02
Preparedisn'tdone

Readiness to act is not the act. The distance between them is where deadlines go missing.

Why this card existsHide
The reasoning

A plan that's ready to execute is not the same as a plan that has executed. Readiness feels like progress because the hard thinking is finished — but nothing has actually happened in the world yet, and the gap between the two is invisible from the inside.

In practice

A policy is finished, signed off, and filed — then rolled out to a team who never see it. On paper the business is compliant. In practice nobody's behaviour has changed.

03
Namedisn'treal

Giving a thing a name creates a reference, not a capability. The label arrives long before the mechanism.

Why this card existsHide
The reasoning

Naming something and placing it in a diagram makes it easy to talk about — which quietly starts to stand in for it existing. A named process is a plan for a process, not the process itself.

In practice

An "escalation procedure" sits on an org chart and in onboarding slides. When something genuinely needs escalating, nobody is sure who actually picks up the phone.

04
Rememberedisn'ttrue

A system recalling something is not evidence it happened. Recall and verification are different acts, and only one of them counts.

Why this card existsHide
The reasoning

A system — or a person — recalling something confidently doesn't verify that it's accurate. Confidence and correctness come from different mechanisms. Only one of them can actually be checked.

In practice

An AI assistant is asked whether a client's paperwork was signed off, and answers yes without hesitation. It's working from an old summary. The paperwork was never completed.

05
Passedisn'tpublished

Clearing review is not release. Something can be entirely correct and still not be out in the world.

Why this card existsHide
The reasoning

Clearing a review means something has been judged fit to go out. It doesn't mean it has gone out. That gap is where good work quietly sits, checked twice and used by no one.

In practice

A report is approved, double-checked, and privately treated as done by everyone involved — while it sits in a drafts folder for a month, because sending it was never explicitly anyone's job.

06
Silentisn'tauthorised

Nobody objecting is not the same as somebody agreeing. Absence of refusal is not permission.

Why this card existsHide
The reasoning

Nobody objecting to a plan in the room is not the same as somebody having actually agreed to it. Silence gets read as consent because that's convenient, not because it's true.

In practice

A proposal goes to five people by email. Two reply "looks good." Three say nothing. The plan proceeds as if all five had signed off.

07
No-blockisn'tapproval

A non-blocking review outcome does not approve, certify, activate, or replace the human decision.

Why this card existsHide
The reasoning

A check reporting nothing wrong is a statement about the absence of a detected problem — not a decision that something is right. Passing through unblocked is not the same as being chosen.

In practice

A piece of content clears an automated compliance scan with no flags raised. That's evidence nothing obviously wrong was found — not evidence a person decided it should go out.

08
A fieldisn'tenforcement

A schema field, a label or a status can record governance intent without enforcing governance behaviour.

Why this card existsHide
The reasoning

A status label or a database column can describe what should happen without anything actually making it happen. The record and the reality can drift apart silently, because nothing is watching to keep them aligned.

In practice

A system has a field for "reviewed by manager," ticked as routine data entry. No review process exists behind the tick. The field looks like governance. It isn't doing any.

09
The error is the join

The one card here that names a place rather than denying an equivalence. Partial corrections sitting alongside old content create two competing meanings — often more dangerous than no correction at all.

Why this card existsHide
The reasoning

Fixing three parts of five and leaving two untouched doesn't produce a smaller error. It produces a document that now contradicts itself — which is harder to trust than one that was simply wrong throughout, because the reader can no longer tell which parts to believe.

In practice

A pricing page is updated for one product line but not two related ones. A reader can no longer tell whether the old prices are stale or the new one is a mistake — the correction has made the whole page less trustworthy than before it was touched.

10
Gatedisn'tinternal

Distribution control is not the same as internal status. External audiences remain external whether public, private, gated, or invitation-only.

Why this card existsHide
The reasoning

Restricting who can see something controls its audience. It doesn't change what that something is. Material behind a login, a password or an invite-only link is still external the moment it leaves your own systems — access control is not a status change.

In practice

A working draft is shared with a small group under NDA "just to get their view." The moment it's outside the building it is an external release, whatever the access list says — and should be held to that standard, not a lower one.

The reserved-word rule

Two words that are not synonyms

Most governance failures we have traced back came down to a single confusion: someone said approved and someone else heard go. So inside this system the two words are reserved, and they are not interchangeable. It costs nothing to adopt and it changes how a team talks within a week.

Stage gate

Approved

A governed movement between stages, inside the system. It means a step has cleared. It is not permission to enter the real world.

Terminal gate

Authorised

The final real-world gate. Reserved exclusively for that last act — the moment a person accepts the consequence. It is never used for an intermediate review stage.

The boundary

What is deliberately not on this page

The doctrine is published in full. The machinery is not, and that is a decision rather than an oversight — so it is worth saying plainly which is which.

Published: every card, complete and unabridged, with the reserved-word rule and the principle underneath both. Nothing here is a teaser for a paid version. There isn't one.

Not published: the runtime that enforces any of it, the internal records, the specific incidents that produced each card, and the control architecture the business runs on. Those are ours, and publishing them would help nobody except a competitor.

The split is not arbitrary. A reflex is useful to you the moment you read it. An implementation is only useful inside the system it was built for. So the part that transfers is given away, and the part that doesn't stays where it is.

Long form

Down the AI Rabbit Hole

Why AI Must Keep a Human Heartbeat. The longer argument behind all of the above — written for people running real businesses rather than for the industry talking to itself.

No charge. It asks for an email address, which is the honest trade and is stated here rather than discovered at the last click. Find it on the main site →

Provenance

About this edition

This page is a published edition of an internal governance record. That distinction matters, so it is stated rather than assumed.

Edition
Public Doctrine v1.2 — DRAFT, card-back content pending Founder review
Status
Current
Prepared
24 August 2026
Contains
Wisdom Infrastructure ten-card spine; the Approved / Authorised reserved-word rule; the Canon v Runtime alignment process
Relationship to source
Derived from the internal canonical record, which remains the controlling source. This edition does not carry the authority of that record and is versioned separately from it.
Amendment
A change to the internal record does not silently rewrite this page. Republication is a separate, deliberate act taken by the founder each time — never automatic, never delegated.
Supersession
Superseded editions are marked as superseded and kept reachable, not overwritten or removed. What this page said before remains checkable against what it says now.
Currency
Because republication is deliberate, this edition can sit behind the internal record. That is why it is dated. A dated edition is honest; a page implying it is always current is not.
What publication does not claim.
These cards describe how we think about governed AI systems. They are not a certificate. Nothing here asserts that every product, tool or workflow we run currently satisfies every card — that would be the exact failure the cards exist to catch. Where we find a gap in our own estate, the practice is to record it, bound it, and say so.

Card 01 says visible isn't usable, so this page prints as a two-page reference sheet — the ten cards and the reserved words, laid out to sit on a wall or go round a table. Ctrl /  + P.