An AI system that produces confident product claims is easy to build and hard to trust. Sightspool's design spends most of its complexity on the opposite problem: making certain claims impossible to make. These are not prompt instructions asking a model to behave. They are properties of the system — enforced in code and in the database, and covered by tests.
No proof, no post
Any finding stating a metric or raising an alert must cite the live tool call that produced its number, and the quoted figure must trace back to that call's actual output. Citations must belong to the agent that posted them. A finding that fails these checks is rejected before it publishes, and the database rejects it independently — so the rule holds even if application code is wrong.
Still gathering is not a verdict
Every signal carries a sample floor. Below it, the register reports exactly how far it has to go and rules nothing. There is no configuration that lets a thin read become a verdict, because the cost of a confident wrong answer is far higher than the cost of waiting.
A missing event is not a zero
Sightspool discovers what your sources actually emit rather than assuming a signal's events exist. If an assumption depends on an event that has never been seen, that is surfaced as something you cannot measure yet — a prompt to fix the instrumentation — not as a measurement of zero. Conflating the two is one of the most common ways analytics misleads teams.
An agent never rules verified
A measured read can move an assumption to holds or refuted. Verified is reserved for a human, as is reopening a settled question. Expert judgment from a specialist lens is recorded as evidence in its own right — it never becomes a measurement, because judgment and measurement are different things and collapsing them would corrupt both.
No proof and no approval, no act
Anything that touches your users — a survey, a message, a study, a demand probe — must be justified by either a proof-gated finding or an approved research brief, and must be approved by a human before it can be served. An agent proposes; it cannot approve, cannot launch, and cannot reach your users through any API. You can edit what a proposal says before approving it, but not its evidence: the proof stays fixed to what was actually found.
A painted door always discloses itself
When a demand probe tests interest in a feature that does not exist, the person who clicks is told so immediately. That disclosure is fixed text: it cannot be edited by us, by an agent, or by you. Any attempt to serve a probe without it fails at three independent layers. A measurement technique that depends on misleading your users is not one we are willing to ship.
You decide
Sightspool owns the customer evidence, the focused research and the senior read. Goals, roadmap, priorities and the final call stay with your team. When a senior practitioner is involved, they advise — the decisions that commit your product or your money remain yours, enforced as a permission rule rather than a convention.