Hetu.
Platform / Architecture

Three attempts. Each one knows what it is allowed to claim.

The cascade exists so that certainty is not manufactured. A tier that cannot meet its own criteria hands the question up rather than answering it approximately.

01The cascadeSection 1 of 3

Three methods, each allowed to claim less than the last.

A layer that cannot meet its own bar hands the question up instead of guessing.

Rules

Exact

Failure patterns your experts already recognise, encoded as explicit traversals. If one matches, the answer is not an estimate.

Causal model

Attributed

A fitted graph spreads the anomaly across candidate causes, with intervals it will not round away.

44% · CI 37–51
26% · CI 19–33

Language, last

Hypothesis

Three ranked guesses at most, each with a test that would settle it. Forbidden from naming a cause.

02Stopping criteriaSection 2 of 3

What each tier does, and what stops it.

Tier 1 · Rules

Explicit WHY traversals encoding failure patterns your experts already recognise. No statistics. If the pattern matches, the answer is exact and the label is CONFIRMED.

Exact

A null metric, a sample below the floor, or no matching branch. The miss becomes the spec for the next tree.

Tier 2 · Causal model

A fitted graph attributes the anomaly across candidate causes, with confidence intervals and a residual. The confounder check runs before attribution, not after.

Attributed

Explained variance below 70%, or the top two intervals overlapping. Uncertainty is not rounded away.

Tier 3 · Constrained LLM

A structured payload in, at most three ranked hypotheses out, each with a falsification test. Forbidden from naming a cause or emitting a figure.

Hypothesis

Inability to produce a falsification test. If this tier is the common path, the graph is underspecified.

i

Tier 3 can never name a cause because naming a cause is a claim about the world, and this tier has no evidence — only language. It is allowed to propose what would settle the question, and nothing more.

03Traversals live in configurationSection 3 of 3

A new pattern is an insert, not a deployment.

Traversal trees and the causal graph are rows in a table, not code. A domain expert who recognises a failure pattern can encode it, have it reviewed, and see it live without a release.

That property is what makes the system extend at the speed of the people who understand the domain, rather than the speed of the engineering backlog. It also means every pattern has an author, a date and a review — all of which appear in the audit record when that traversal decides something.

Next

Then read what the guard does with all three.

Every conclusion from every tier passes the same shared checks before an agent sees it.