Skip to content
GridNinja

Proof Before Autonomy

Trust starts with boundaries

GridNinja begins read-only and keeps authority where operators, CISOs, and utilities expect it. If evidence is stale, incomplete, or outside policy, the correct answer is no-proof.

Every accepted MW must point to a proof row.

The autonomy ladder

Shadow to bounded autonomy, with visible evidence at every step

Control authority expands only after operators can inspect the recommendation path, the remaining margin, and the rollback posture.

01

Shadow Mode

Generate recommendations, safety outcomes, and proof artifacts without write credentials or actuation.

unlock: read-only tape

02

Advisory Mode

Operators review action bundles, no-proof gaps, and Load Passport outputs with real decision context.

unlock: operator review

03

Bounded Autonomy

Enable a narrow actuator set only inside declared dispatch envelopes and runtime assurance checks.

unlock: dispatch envelope

04

Expanded Autonomy

Add coordinated multi-asset control as evidence and confidence accumulate.

unlock: evidence gate

Authority boundary

Proof before autonomy means the system can say no

GridNinja can propose and verify candidate actions, but live authority stays inside declared site policy, deterministic checks, runtime assurance, and operator review.

Read-only Shadow Mode first
No write credentials in first deployment posture
No command VLAN requirement for proof generation
No hidden actuation path from ML, frontend state, or fleet software
Operator policy and runtime assurance remain the approval boundary

Runtime Assurance

Every candidate resolves to allow, repair, reject, or no-proof.

Deterministic verification checks the active dispatch envelope before a receipt and replayable proof record are produced.

  • Proposal
  • Solver
  • Runtime assurance
  • Receipt
  • Replay
  • Proof

Proof chain

Proposal to proof pack with authority boundaries visible

proof_root: 8f4c...91a

Can do

Rank candidate workload, cooling, and bridge-power bundles.

Cannot do

Cannot approve site actions or mutate authority.

Same tape, same proof root

Replay should return the same evidence root

Tape

URI_STRESS_2021_02_15

Topology

ATL1_v0.3

Policy

SHADOW_READ_ONLY

Run 1

T+00:18

pending replay
run_id: pending
event_tape_hash: pending
topology_hash: pending
policy_hash: pending
proof_root: pending

Run 2

T+00:42

pending replay
run_id: pending
event_tape_hash: pending
topology_hash: pending
policy_hash: pending
proof_root: pending

same tape + same topology + same policy = proof_root 8f4c...91a

AI Data Center Load Passport

One inspectable identity for proof-adjusted capacity.

The Load Passport binds accepted capacity to ramp limits, reserve floors, freshness, no-proof gaps, and accepted-headroom evidence.

  • Declared operating policy
  • Binding constraints and margins
  • Evidence-chain status
  • Versioned proof root

Constraint braid

The RTA decision inherits every active constraint

The proof chain stays legible by showing which power, cooling, storage, workload, or telemetry trust constraint produced allow, repair, reject, or no-proof.

Constraint braid

Constraints converge before capacity is accepted

REPAIR

Binding constraint

Transformer T2 ramp envelope

Proof object

Capacity Waterfall row 002

Accepted posture

Repair to declared ramp limit before acceptance

source

EPMS-A + PCC telemetry

constraint

T2_RAMP_LIMIT

proof_row

waterfall.power.row_002

Fleet evidence

A fleet panel can compare proof posture without approving actions

This view is read-only evidence aggregation. Local site policy, operator review, and runtime assurance remain the authority boundary.

Fleet evidence

Fleet comparison without fleet-side actuation authority.

FleetOS aggregates signed site envelopes, proof roots, accepted headroom, and no-proof gaps while local policy remains the authority boundary.

  • Signed site envelopes
  • Accepted-headroom ledgers
  • No-proof registers
  • Local authority preserved

Artifact gallery

Operator-readable proof objects, not just recommendations

GridNinja produces the Load Passports, ledgers, reports, registers, and packets needed to evaluate virtual capacity before bounded autonomy.

Operators, hyperscalers, investors

AI Data Center Load Passport

A site-specific capacity identity that summarizes proof-adjusted virtual capacity, binding constraints, freshness posture, and declared operating policy.

Illustrative sample · evidence chain complete

Executives, operators, reviewers

Capacity Waterfall

A transparent reduction from nominal headroom to safe, usable, auditable capacity after electrical, reserve, thermal, workload, and telemetry checks.

Illustrative sample · evidence chain complete

Operators, auditors, fleet teams

Accepted-Headroom Ledger

A time-indexed record of accepted capacity states, rejected actions, no-proof intervals, and the proof root behind each decision.

Illustrative sample · evidence chain complete

Facilities, BESS/UPS partners

Reserve-Floor Report

A resilience-first view of UPS, BESS, and bridge-power margins so flexibility does not spend emergency posture silently.

Operators, CISOs, program owners

No-Proof Gap Register

A remediation list for missing telemetry, incomplete topology, stale policy, or weak evidence that prevents safe approval.

Utilities, EMCs, partners

Utility Evidence Packet

A planning-facing summary of flexible MW, ramp limits, reconnection envelope, confidence posture, and exceptions.

No-proof register

Missing evidence becomes visible remediation

Telemetry freshness

High severity

Open

-1.2 MW proof discount

Confirm 15-second freshness across feeder, reserve, thermal, and workload nodes.

Topology mapping

High severity

In review

no-proof for thermal envelope

Bind rack groups, feeders, cooling zones, UPS strings, and bridge assets to one proof graph.

Policy declaration

Medium severity

Required

no reserve-safe dispatch

Declare reserve floors, SLA exclusions, allowed repair bands, and rollback posture.

0 of 3 gaps marked verified in this illustrative register. Sample recovered capacity: +0.0 MW.

Utility evidence packet

Planning value without pretending to be a utility approval

GridNinja translates local proof into evidence utilities and energy market coordinators can inspect. It does not replace interconnection studies, tariff requirements, or operator authority.

  • Flexible MW by interval
  • Ramp-rate envelope
  • Safe reconnection envelope
  • Telemetry confidence and exceptions
  • No-proof gaps and remediation owners

Audit log example

Readable, attributable, and grounded in the active constraint

Every repair or rejection is logged in plain operator language, with the relevant envelope and predicted impact attached.

Safety and rollback

GridNinja can operate in monitoring-only Shadow Mode, advisory mode, or bounded autonomy. The first deployment posture is read-only: no write credentials, no command VLAN, no hidden actuation path, and no approval authority delegated to ML, LLMs, frontend state, or fleet-level software.

Operator FAQ

Does GridNinja need control access on day one?

No. The first posture is Shadow Mode evidence generation with read-only telemetry and no hidden actuation path.

What happens when telemetry is delayed or ambiguous?

The result is no-proof until freshness, topology, or policy evidence is strong enough to support a safe answer.

Can Fleet-level software approve site actions?

No. Fleet views can aggregate proof objects, but local site policy and operator authority remain the approval boundary.

CISO FAQ

What credentials are required for Shadow Mode?

The intended first deployment uses read-only data paths scoped to explicit telemetry sources and logging boundaries.

How are exports handled?

Proof artifacts should be gated, redacted where needed, and traceable to a source, policy, and export event.

What is the failure mode?

If trust assumptions break, GridNinja fails closed into no-proof instead of presenting unsafe capacity as accepted.

Sample proof pack

Review the artifact stack before the first call

Open the full proof-pack surface or download the sample bundle to inspect logs, envelopes, and Shadow Mode artifacts before a live demo.

Capacity Audit

Start with Shadow Mode evidence, then expand control with proof in hand

Use Capacity Audit and Shadow Mode outputs to establish the business case, the active constraints, and the operating guardrails before bounded autonomy.