One server. One database. Six invariants.
Cascadian is one MCP server in front of one Postgres — 17 tables under a tritemporal envelope. History is append-only, and every fact carries when it was true and when you learned it.
Five gifts between a question and a decision.
A question enters; a defensible decision leaves. Every gift is callable over MCP, and every answer carries its evidence, its assumptions, and the time it was knowable.
Tritemporal · governed · scoredWhat was known, and when. Every fact carries when it was true and when you learned it — history is append-only.
Humans own truth, agents propose. Edges arrive with rationale and evidence — and wait for approval.
No effect estimate without a valid basis — backdoor, frontdoor, instrument, or a declared design. Otherwise: exploratory only, and labeled.
The ripple, with honest uncertainty — per-variable expected change, intervals, the causal path, and every assumption on it.
Frozen expectations, scored outcomes — variance diagnosed, learning proposed, judgment compounding.
Every decision is graded by reality.
A decision that is never scored is just an opinion. Cascadian closes the loop under governance: expectations are frozen before you act, outcomes are recorded against them, variance is diagnosed — and the lesson waits for a human signature.
Freeze
Before you act, the recommendation freezes its expected outcome — what should happen, and by when. No retroactive editing.
Record
When reality settles, the measured actuals are recorded, and expected-vs-actual is computed against the frozen expectation.
Diagnose
Variance gets a diagnosis, not a shrug — which assumption broke, which edge was overconfident, what context was missing.
Propose
Learning updates are proposed — a human approves them — and the next decision's context is smarter. Nothing self-corrects.
Six things the substrate physically cannot do.
These are not policies. They are structural — enforced by the schema and the server, not by good intentions.
History is never overwritten
Every write is append-only. Corrections supersede; they never erase. The past stays exactly as it was recorded.
No future leaks into the past
Every query pins a moment in time, and only what was knowable then can appear. Lookahead is a violation the server detects.
No estimate without identification
An effect estimate requires a valid identification strategy first — backdoor, frontdoor, instrument, or a declared design. Otherwise it is exploratory, and labeled.
No hidden scores
Every number arrives with its assumptions, its diagnostics, and its skeptic findings. There is no internal score you can't see.
Agents only propose
Claude proposes facts, edges, and learning; humans approve them — via a CLI token that never crosses the AI boundary.
No high-risk action without sign-off
Decisions at or above medium risk require a granted approval before they commit. The ledger enforces it.
417 sources in. One calibrated number out.
Prediction markets, filings, flows, and analogs — weighted by causal relevance, stress-tested in simulation.
Every answer carries its receipts.
Each decision pins its context — the facts, beliefs, and graph version it was made on. Re-run the pinned queries later and diff the result; the diff is the audit artifact.
Agents only propose — facts, edges, learning. Approval happens through a CLI token that never crosses the AI boundary. Your data and your decisions stay yours.
Wire the substrate into your agents.
One MCP server puts the whole loop behind your agent’s next decision. We’ll scope a pilot to a single live decision.
Request a briefing →

