The Document Engine · version 2
One PDF. One evidence contract. Every uncertainty exposed.
Version 2 inventories every source page before extraction, resolves typed evidence into one authoritative graph, validates omissions and relationships, and binds the route and HTML to one immutable result. Independent accuracy measurement remains a separate gate.
Automated conversion assists accessibility work. It does not certify WCAG, PDF/UA, ADA, or Section 508 conformance. The exact output version still requires the applicable human and assistive-technology review before publication.
- Engine
- document-engine-v2
- Graph
- schema 2.0
- Policy
- document-release-policy-v2
- Publication
- version-bound human release
Interactive system map · schema 2.0
Follow one PDF through the engine
Select a stage to inspect its decision, retained evidence, and fail-safe behavior. The animation never changes the underlying result.
Inspect the source
The engine fingerprints the exact file and creates an immutable page ledger before extraction chooses an adapter. Media boxes, rotation, decoded text, imagery, vectors, OCR provenance, and tag presence stay source-bound.
- Decision
- Is there trustworthy tag structure, a usable text layer, page imagery, or evidence that text recovery is needed?
- Evidence retained
- SHA-256 source identity
- Page geometry and object locations
- Tag-tree and text-layer quality signals
- Scan, image, table, form, and language signals
- False-safe protection
- An unreadable or partial source cannot silently become an HTML-first candidate.
Authority, not another converter
The target: one source of truth with four jobs.
Adapters gather evidence. The graph must own meaning. Validators own deterministic findings. The release policy owns routing. Schema 2.0 enforces that boundary: projections and policy read typed graph fields, while legacy payloads remain a debug-only compatibility snapshot.
Collect source evidence
Extraction adapters inspect the exact file and report page, region, object, and method evidence. They can disagree or remain uncertain; none is independently authoritative.
pipeline adaptersNormalize meaning
Schema 2.0 resolves typed fields and relationships into stable semantic nodes. Competing adapter values remain explicit assertions; conflicts resolve to cannot-tell instead of inheriting an adapter guess.
document_engine.graphValidate relationships
Deterministic checks inspect heading order, table grids and headers, links, form behavior, formula semantics, node identity, and completeness against the same graph.
document_engine.validatorsRoute, then release
One policy explains the safest next operational path. A separate version-bound human decision controls publication, so routing confidence cannot become an automatic release.
document_engine.policy
Field-level provenance
Every resolved field can show its work.
The engine does not attach one vague confidence value to an entire page. A node’s semantic type, content, and language can each have different evidence, outcomes, methods, and review states.
- Node
- A stable heading, paragraph, list, figure, table, form, formula, note, or other semantic object.
- Field
- A resolved decision such as semantic type, content, or language—never a document-wide guess.
- Assertion
- The method, four-state outcome, review state, and evidence identifiers supporting that field.
- Source segment
- The page, bounding box, object or character locator, document order, and extraction method when available.
Fail closed
Knowing when not to automate is part of the engine.
These conditions route to review or specialist handling. They are not softened into a reassuring score or silently removed from the output.
- Partial or truncated output
- No usable semantic content
- Unresolved OCR or required source comparison
- Forms whose labels, groups, instructions, or submission behavior need verification
- Mathematical notation without verified semantics and spoken output
- Complex tables or numeric layouts whose relationships were not preserved
- Meaningful image sets with unresolved purpose or alternatives
- Exact-layout, signature, map, legal-filing, or pagination constraints
The one-engine acceptance gate
What “achieved” actually requires.
The graph-authority and release-safety foundation is implemented, but independently measured accuracy is not something code can declare on its own. These ten gates separate enforced foundations, engineering still required, and independently labelled measurement or exact-version review.
- Every production ingestion surface creates the same schema version and uses the same policy.Foundation enforced
Remediation, editor saves, deterministic previews, and visual transcripts finalize schema 2.0 EngineResults. Request triage is explicitly pre-document; publication consumes only the graph-bound result.
- Reprocessing unchanged source bytes is structurally deterministic.Foundation enforced
Stable node identifiers derive from source identity, semantic type, source location, a content fingerprint, and only a duplicate occurrence counter—unrelated insertions do not renumber the document.
- Meaningful content and relationships meet approved per-class thresholds.Measurement required
Text, order, block types, headings, lists, links, figures, tables, forms, formulas, notes, and language changes still need frozen holdout measurements.
- Mixed born-digital and scanned PDFs select the correct strategy per page and region.Engineering required
Schema 2.0 inventories every page before extraction and records candidate and selected adapters. Page-level selection is enforced; finer coherent sub-page segmentation and labelled strategy accuracy are still required.
- Cross-page continuations meet approved precision and recall thresholds.Measurement required
Paragraph and table reconciliation fail closed today, but their class-specific precision and recall still need independent labels.
- Cannot-tell, provider failure, truncation, and invalid relationships never become a release pass.Foundation enforced
Typed field resolution, page and region dispositions, provider-state checks, graph validators, and exact-result identity failures all fail closed. Human review is still required for cannot-tell criteria.
- The specialist-route false-safe rate meets an approved holdout threshold.Measurement required
The policy is deterministic and explainable; safe threshold calibration still requires adjudicated holdout results.
- Keyboard, 400% reflow, and representative screen-reader tasks pass on the exact output.Measurement required
These are exact-version human and assistive-technology checks, not properties an extraction score can establish.
- A human release record is bound to the exact immutable version before publication.Foundation enforced
The release gate is separate from automated routing so a later edit cannot inherit an earlier approval.
- Benchmark artifacts, labels, disagreements, and results are reproducible and consistent.Measurement required
The public pilot provides the starting evidence; independently labelled holdout evaluation and adjudication remain required for accuracy claims.
See the evidence
Try the engine, then inspect the limits.
Convert a PDF in the public preview, examine the published benchmark method, or review the research program behind future accuracy decisions.
Engine assurance summary
The engine records evidence and routes uncertainty. Human release evidence remains bound to the exact published version.