Skip to main content

Evidence

What works today, and what does not.

Every capability below is read from a typed inventory that Alodai keeps in its own repository. Each card says what it promises, how far it has got, who can use it, and what it does not do.

The evidence law

A claim is only as strong as its evidence.

Built means the code exists and its automated tests pass. Tested means someone ran it on a real stack and wrote the run down. Proven means that written run carries a date.

None of that means live for the public. A recorded run is a record of a test, not an observation of production. This page never shows a capability as live, and a planned capability is never shown as available.

Status is worked out from the evidence, not written by hand. When a limitation could change a buying decision, it sits on the card next to the promise.

Legend

How to read a card.

Status

Planned
Intended, with no working code behind it. Not available.
Built
The code exists and its automated tests pass. No run on a real stack is on record.
Tested (recorded run)
A run on a real stack is written down. It may be old, and it is not a production observation.
Proven (recorded run, dated)
As tested, and the written run carries a date, shown on the card.

Access

Managed by Alodai
Alodai sets it up and operates it for you.
Self-serve
You can use it without Alodai setting it up for you.
Internal only
Used by Alodai. Customers cannot use it.
Not available
Customers cannot use it today.

Organization

Structure, access and the company itself.

  • Built

    Organization structure and access

    Organizations own units, delivery projects and brands, with inherited Console role bindings for scoped human access.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • This covers account and resource governance, not incorporation, shareholder governance or a complete policy engine.
    • Some platform and site records are not yet required to belong to a project, and platform users and API keys are separate identity systems.
  • Planned

    Company formation and corporate governance

    Coordinate formation, corporate documents, obligations and qualified provider handoffs around an organization’s context.

    Access
    Not available
    Evidence
    No evidence yet

    What it does not do

    • Planned direction only: no end-to-end incorporation, statutes, shareholder-agreement, cap-table or statutory filing workflow exists today.
    • Fiscal issuer records and privacy notices exist as narrower capabilities and do not deliver this promise.

Business

Running the work: customers, sales, projects, payments.

  • Built

    Payments

    Checkout code for Alodai billing its own organisations and for paid course enrolment on a platform, with money held as integer cents.

    Access
    Not available
    Evidence
    Code only, no recorded run

    What it does not do

    • The payment provider is not switched on in production, so every payment call fails.
    • Paid checkout has never run end to end, not even in test mode.
    • A platform cannot take payments from its own customers: the only payment path bills organisations at Alodai's own prices.
    • There are no orders, stock, shipping or order history.
  • Proven (recorded run, dated)

    Document intake

    A PDF with a text layer is extracted by a model into typed fields, and a person reviews and approves them in a cockpit with an append-only log.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-08-03

    What it does not do

    • There is no OCR: a scanned PDF without a text layer fails and no fields are written.
    • PDF is the only accepted format, and input beyond 20,000 characters is cut off and flagged, not split into parts.
    • The module is in beta and off by default, and no recorded run exists in production.
  • Proven (recorded run, dated)

    Scheduling and booking

    Recurring class schedules, member bookings with a capacity guard, a first-come waitlist that promotes on cancellation, and a manager roster.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-07-02

    What it does not do

    • Bookings are not linked to memberships, credits or payment: the entitlement check always allows.
    • A booking sends no email or notification.
  • Proven (recorded run, dated)

    Leads and enquiries

    A published site's form captures an enquiry into the platform's Admin Panel, where it is read, starred, archived, answered or erased.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-09-16

    What it does not do

    • A new enquiry sends no email to the platform owner.
    • A site with no linked platform cannot capture enquiries at all.
    • The inbox is not paginated, and erasing enquiries works one at a time.
  • Built

    CRM records

    Maintain platform-scoped contacts, companies and leads for business work.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • Records and pages only: there is no full CRM automation suite and no customer graph shared across an organisation.
    • It has not been freshly verified in production or end to end.
  • Built

    Commercial documents and finance records

    Manage explicit fiscal issuers and commercial document transitions, with project economics and expense records.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • Issuing a document is not payment settlement, a statutory filing, a qualified signature, a general ledger or payroll.
    • Legal entities belong to a single platform; an organisation-wide company entity model and accounting-software integrations do not exist.
  • Built

    Projects, tasks and workforce

    Track platform projects, milestones, tasks, relations and workforce records through scoped modules.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • Platform projects are separate from Console delivery projects, and there is no automatic outcome graph across domains.
    • Workforce records and exception workflows are not payroll or employment compliance.

Digital

Sites, apps and the platforms they run on.

  • Proven (recorded run, dated)

    Platform apps

    An authenticated app for each customer platform, created and configured in the Console, served from one image at its own subdomain or a custom domain.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-07-02

    What it does not do

    • A verified custom domain does not work until Alodai also adds it to the hosting configuration by hand.
    • When the lookup for a platform is rate-limited, the app quietly shows a fallback platform instead of an error.
    • There is no automated release pipeline: every deployment is a manual run.
  • Proven (recorded run, dated)

    Genesis

    A written brief compiles, in staged and resumable passes, into a draft platform and site that a person reviews before anything goes live.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-07-03

    What it does not do

    • Without the AI model available, it falls back to fixed rules that can choose the wrong experience pack and colours.
    • It can publish a site whose pages failed to generate, and it always creates the site with an English locale.
    • No recorded run compiles a brief in production.
  • Proven (recorded run, dated)

    Modules

    Capabilities are switched on per platform from one registry, and a module marked as not yet built cannot be enabled for a platform — the core service refuses it.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-07-02

    What it does not do

    • Only a new activation is refused: a platform that already had an unfinished module switched on keeps it until someone switches it off.
    • Permission enforcement for modules is selective, so not every permission is checked at runtime, and organisation role inheritance is a separate system.
    • A module marked stable can be missing the data table it needs.
  • Proven (recorded run, dated)

    Experience packs

    A pack configures a platform for a vertical — modules, copy, navigation and seed content — without owning any data.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-07-02

    What it does not do

    • The instructions and safety rules a pack declares for AI agents are not passed to the model today.
    • Four experience types offered on platforms (creator, directory, intranet and marketplace) have no pack behind them yet.
  • Proven (recorded run, dated)

    Sites

    A public site assembled from governed blocks and published at a site subdomain or a custom domain, with no app to deploy.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-09-18

    What it does not do

    • A custom domain does not work until Alodai adds it to the hosting configuration by hand.
    • Published pages are cached for up to 60 seconds, and a page that was removed can keep being served.
    • Access rules for Sites are being reconciled with recent security changes, and the documentation of them is not yet up to date.
    • Live sites show a cookie consent banner without a linked privacy notice.
  • Proven (recorded run, dated)

    Media and storage

    Uploaded files stored as private objects under stable keys and served through URLs signed at read time, with public assets for published sites.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-08-21

    What it does not do

    • No recorded run proves reading private files through signed links in production.
    • A stored item's platform label is taken from the caller without being checked.
    • Public assets accept images only; video and other file types are refused.
  • Proven (recorded run, dated)

    World Quest

    A travel experience on a customer platform: a map of expeditions, a narrated guide, questions at each stop and a passport of places visited.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-07-28

    What it does not do

    • Proven on development stacks only: production content differs from the development content, and no run against production is on record.
    • The travel pack declares agents that have no working handlers.
    • A GPS check-in does not prove a physical visit.
  • Built

    Extensions

    Install code-shipped platform capabilities through registered manifests and platform configuration.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • Extensions are different from the content blocks used to build sites.
    • A registered manifest does not prove every handler works, and customers cannot upload their own code.

AI

Where AI proposes and people decide.

  • Built

    AI gateway

    Four model providers behind one router, a spend guard in front of every call, and bring-your-own keys at organisation and platform level.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • No recorded run has exercised the router, the spend guard or a customer's own key on a real stack.
    • The model catalogue can be browsed, but the router does not choose from it.
    • The executor that runs AI capabilities refuses AI-provider ones, so some contracts that claim to execute do not.
  • Proven (recorded run, dated)

    COS and Cortex

    COS proposes bounded business actions through an allowlisted kernel and approval ledger; Cortex separately recommends engineering run plans without executing them.

    Access
    Not available
    Evidence
    Recorded run, not a production observationRun dated 2026-07-03

    What it does not do

    • Proven on a stand-in platform only; it has not been deployed to production.
    • Autonomy is capped: every action is proposed and waits for a person to approve it.
    • Only two departments exist, Finance/Admin and Workforce Ops, and Cortex plans over test fixtures and a saved snapshot, not live data.

Cloud

The infrastructure underneath.

  • Built

    Infrastructure operations

    The estate runs on Alodai-operated servers in Europe: Docker Swarm behind Traefik with automatic TLS, data on its own host, monitoring, alerting and off-site backups.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • A restore from backup has never been proven, and no disaster-recovery drill has run.
    • Most alert rules refer to metrics that nothing produces, so they cannot fire.
    • Deployments are manual runs from the founder's workstation, because the automated build pipeline is not running.
    • The infrastructure's own audits are kept outside this inventory, so it is shown as built, not as a recorded run.
  • Planned

    Infrastructure Control Plane

    A control plane that lets an operator see and change the estate — domains, services and hosts — from one governed surface.

    Access
    Not available
    Evidence
    No evidence yet

    What it does not do

    • Not available yet. Planned: one governed place to see and change domains, services and hosts. Today's domain tools and managed hosting do not amount to this.

Shared foundations

Accounts, email, storage and the other pieces every domain relies on.

  • Proven (recorded run, dated)

    Hub

    One account for the people who use Alodai-built platforms, and one click from the launcher into a platform, already signed in.

    Access
    Self-serve
    Evidence
    Recorded run, not a production observationRun dated 2026-09-08

    What it does not do

    • The link is one-way: from inside a platform there is no way back into the Hub.
    • Hub accounts have no second factor and no sign-in through an outside provider.
    • The account facts feature is built but not proven in production, and a grant can name a platform the account is not a member of.
  • Proven (recorded run, dated)

    Identity and tenancy

    Sign-in, sessions and roles for every platform, with each request checked against its tenant in the service code before it touches a row.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-08-19

    What it does not do

    • Single sign-on through SAML does not work: every callback fails.
    • Tenant checks are written into each service's code rather than enforced in one place, so every change needs its own check; recent fixes cover specific access paths, not every module or provider integration.
    • Organisation-level role inheritance exists, but permission enforcement inside platform modules is selective and is not a universal guarantee.
  • Built

    Reality Ledger

    Claims about system state recorded with their evidence, source tier, freshness and confidence, with standing derived rather than stamped.

    Access
    Internal only
    Evidence
    Code only, no recorded run

    What it does not do

    • Contracts and helpers only: there is no store, no detector for contradictions or stale claims, and no command-line tool yet.
    • Its only reader today is an internal planning tool, and the capability inventory does not feed into it.
  • Tested (recorded run)

    Transactional email

    Account and product email rendered from stored templates with per-platform branding and sent through a queue.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun date not recorded

    What it does not do

    • The recorded end-to-end run delivered to a local mail catcher, not through the production email provider.
    • A reported password-reset non-delivery has no confirmed cause, and when delivery is disabled the system still logs mail as sent.
    • Tenants cannot override templates, and the email provider is chosen once for the whole estate.
  • Proven (recorded run, dated)

    GitHub connection

    An organisation installs Alodai's GitHub App and links repositories, whose activity is read into the platform on request.

    Access
    Managed by Alodai
    Evidence
    Recorded run, not a production observationRun dated 2026-09-07

    What it does not do

    • Proven against a stand-in for GitHub, never against GitHub itself.
    • There are no webhooks or polling: data is only as fresh as the last manual read.
    • During setup, an installation can be claimed by another organisation.
  • Proven (recorded run, dated)

    Docs

    Public product documentation at docs.alodai.com, readable by anyone without an account.

    Access
    Self-serve
    Evidence
    Recorded run, not a production observationRun dated 2026-09-10

    What it does not do

    • There is no public API reference; it stays internal until a public API exists.
    • Two getting-started pages are placeholders.
  • Built

    AOM operator governance

    Record operator delegations, reviews, decisions and outcomes, with advisory enrichment of persisted redacted transcripts.

    Access
    Internal only
    Evidence
    Code only, no recorded run

    What it does not do

    • Recording only: it cannot dispatch work, deploy, merge or provision infrastructure.
    • It is an operator cockpit, not a customer-wide control tower, and the agent operating agreement is a separate process document.
  • Planned

    Unified Control Tower

    One governed view across the organization: what matters now, what changed, who owns it, what needs approval, what evidence supports it and what happens next.

    Access
    Not available
    Evidence
    No evidence yet

    What it does not do

    • Not available yet. Planned: one place to see what matters, who owns it and what needs approval. Today the pieces are separate screens for organization access, operator records, approvals and infrastructure monitoring.
  • Built

    Integration channels

    Dispatch configured integration events through provider adapters and queued delivery.

    Access
    Managed by Alodai
    Evidence
    Code only, no recorded run

    What it does not do

    • Only Slack, Discord and Telegram are supported today; this is not a catalogue of every business integration.
    • Each connection's credentials, delivery and failure handling need checking per customer, and no new connection was tested for this inventory.

Evidence · next step

Want to know what fits your organization?

Tell us what you need to run. We will tell you which of these is real today and which is not.

Discuss your organization