You already built this once.

A spreadsheet, a Notion board, a Postgres table with a dedupe hash and a Slack bot.

It demoed great.

Six months later nobody opened it.

It didn’t fail because you built it badly.

It failed because it collected findings instead of recording decisions.

Findings pile up at machine speed. Decisions happen at human speed.

Any list that doesn’t separate the two becomes the same thing: a place you put things you never intend to look at again.

800 criticals. 15 real issues. Zero memory.

Scanners are cheap now; findings are cheaper.

The scarce things are: evidence you can check, a decision with a name on it, and a record that still answers a year later.

A dashboard shows you today. It cannot tell you what was proven, what was waived and why, what an agent was allowed to touch.

That history is the part an auditor asks for — and the part that dies first in every home-built tracker.

The only shape that survives contact.

Three properties, and every one of them is structural, not a feature:

Kloudle · The three properties Structural · Sheet 1 of 1
1

Promotion is the entry ticket.

A finding gets in only when its evidence is attached. That’s the filter your backlog never had.

800 maybes stay outside; issues get in.

2

Decisions are the rows.

Fix, waive with a reason and an expiry, or accept. Every row is signed: by a person, by a policy with its version, or by an agent.

Policy clears the routine at machine speed; humans get what escalates.

A policy decision records the policy version that fired — “auto-waived by policy P-14 v3” is the line an auditor wants. Scope is structured — check, resource, action, nothing wider: the boundary an agent reads before it acts.

3

Append-only, in your database.

The app can only insert; update and delete are revoked at the database itself. Rows are hash-chained, so tampering shows with nothing but psql.

Evidence lives by reference, so the record stays small. pg_dump is the exit: the history outlives the tool, the vendor, and the sprint.

Remove one and the shape collapses End of sheet

Take any one away and you’re rebuilding your dead tracker with better fonts.

Same finding. Opposite verdict.

Two public buckets. The identical failing check. Watch what promotion does with them.

bucket-a · static website assets

Serves a public site. Nothing sensitive writes to it.

auto-waived · by policy, version recorded
bucket-b · behind a CDN origin

A deploy role writes here. The internet can reach it through the CDN.

promoted · Critical · queued for a human

Same scanner line. Opposite outcome. What connects to the bucket decides, and the row records why.

The decision machinery is Near-term, as labeled below. This is what it’s being built to do.

What an entry holds.

01Observed
02Proven
03Promoted
04Recorded
05Decided
06Acted
07Verified

The full anatomy, with a real sample entry, is on the home page.

Walk the seven stages →

What runs today. What doesn’t yet.

Live today

Evidence-backed findings and the record run today.

Near-term

The decision stages are being built on the shipping engine.

Destination

Agents acting from the ledger is the destination, and it’s labeled that way everywhere it appears.

Bring the tracker that died.

Tell me what it did well before it drowned. That’s the spec we’re building against.