The Document Engine · version 2

One PDF. One evidence contract. Every uncertainty exposed.

Version 2 inventories every source page before extraction, resolves typed evidence into one authoritative graph, validates omissions and relationships, and binds the route and HTML to one immutable result. Independent accuracy measurement remains a separate gate.

Automated conversion assists accessibility work. It does not certify WCAG, PDF/UA, ADA, or Section 508 conformance. The exact output version still requires the applicable human and assistive-technology review before publication.

Engine
document-engine-v2
Graph
schema 2.0
Policy
document-release-policy-v2
Publication
version-bound human release

Interactive system map · schema 2.0

Follow one PDF through the engine

Select a stage to inspect its decision, retained evidence, and fail-safe behavior. The animation never changes the underlying result.

Schema 2.0 inventories source pages before extraction, resolves typed evidence into one graph, and routes only from an immutable finalized result. Independently labelled accuracy and exact-version human review remain separate evidence gates.
Stage 1 of 5

Inspect the source

The engine fingerprints the exact file and creates an immutable page ledger before extraction chooses an adapter. Media boxes, rotation, decoded text, imagery, vectors, OCR provenance, and tag presence stay source-bound.

Decision
Is there trustworthy tag structure, a usable text layer, page imagery, or evidence that text recovery is needed?
Evidence retained
  • SHA-256 source identity
  • Page geometry and object locations
  • Tag-tree and text-layer quality signals
  • Scan, image, table, form, and language signals
False-safe protection
An unreadable or partial source cannot silently become an HTML-first candidate.

Authority, not another converter

The target: one source of truth with four jobs.

Adapters gather evidence. The graph must own meaning. Validators own deterministic findings. The release policy owns routing. Schema 2.0 enforces that boundary: projections and policy read typed graph fields, while legacy payloads remain a debug-only compatibility snapshot.

  1. Collect source evidence

    Extraction adapters inspect the exact file and report page, region, object, and method evidence. They can disagree or remain uncertain; none is independently authoritative.

    pipeline adapters
  2. Normalize meaning

    Schema 2.0 resolves typed fields and relationships into stable semantic nodes. Competing adapter values remain explicit assertions; conflicts resolve to cannot-tell instead of inheriting an adapter guess.

    document_engine.graph
  3. Validate relationships

    Deterministic checks inspect heading order, table grids and headers, links, form behavior, formula semantics, node identity, and completeness against the same graph.

    document_engine.validators
  4. Route, then release

    One policy explains the safest next operational path. A separate version-bound human decision controls publication, so routing confidence cannot become an automatic release.

    document_engine.policy

Field-level provenance

Every resolved field can show its work.

The engine does not attach one vague confidence value to an entire page. A node’s semantic type, content, and language can each have different evidence, outcomes, methods, and review states.

Node
A stable heading, paragraph, list, figure, table, form, formula, note, or other semantic object.
Field
A resolved decision such as semantic type, content, or language—never a document-wide guess.
Assertion
The method, four-state outcome, review state, and evidence identifiers supporting that field.
Source segment
The page, bounding box, object or character locator, document order, and extraction method when available.

Fail closed

Knowing when not to automate is part of the engine.

These conditions route to review or specialist handling. They are not softened into a reassuring score or silently removed from the output.

  • Partial or truncated output
  • No usable semantic content
  • Unresolved OCR or required source comparison
  • Forms whose labels, groups, instructions, or submission behavior need verification
  • Mathematical notation without verified semantics and spoken output
  • Complex tables or numeric layouts whose relationships were not preserved
  • Meaningful image sets with unresolved purpose or alternatives
  • Exact-layout, signature, map, legal-filing, or pagination constraints

The one-engine acceptance gate

What “achieved” actually requires.

The graph-authority and release-safety foundation is implemented, but independently measured accuracy is not something code can declare on its own. These ten gates separate enforced foundations, engineering still required, and independently labelled measurement or exact-version review.

  1. Every production ingestion surface creates the same schema version and uses the same policy.Foundation enforced

    Remediation, editor saves, deterministic previews, and visual transcripts finalize schema 2.0 EngineResults. Request triage is explicitly pre-document; publication consumes only the graph-bound result.

  2. Reprocessing unchanged source bytes is structurally deterministic.Foundation enforced

    Stable node identifiers derive from source identity, semantic type, source location, a content fingerprint, and only a duplicate occurrence counter—unrelated insertions do not renumber the document.

  3. Meaningful content and relationships meet approved per-class thresholds.Measurement required

    Text, order, block types, headings, lists, links, figures, tables, forms, formulas, notes, and language changes still need frozen holdout measurements.

  4. Mixed born-digital and scanned PDFs select the correct strategy per page and region.Engineering required

    Schema 2.0 inventories every page before extraction and records candidate and selected adapters. Page-level selection is enforced; finer coherent sub-page segmentation and labelled strategy accuracy are still required.

  5. Cross-page continuations meet approved precision and recall thresholds.Measurement required

    Paragraph and table reconciliation fail closed today, but their class-specific precision and recall still need independent labels.

  6. Cannot-tell, provider failure, truncation, and invalid relationships never become a release pass.Foundation enforced

    Typed field resolution, page and region dispositions, provider-state checks, graph validators, and exact-result identity failures all fail closed. Human review is still required for cannot-tell criteria.

  7. The specialist-route false-safe rate meets an approved holdout threshold.Measurement required

    The policy is deterministic and explainable; safe threshold calibration still requires adjudicated holdout results.

  8. Keyboard, 400% reflow, and representative screen-reader tasks pass on the exact output.Measurement required

    These are exact-version human and assistive-technology checks, not properties an extraction score can establish.

  9. A human release record is bound to the exact immutable version before publication.Foundation enforced

    The release gate is separate from automated routing so a later edit cannot inherit an earlier approval.

  10. Benchmark artifacts, labels, disagreements, and results are reproducible and consistent.Measurement required

    The public pilot provides the starting evidence; independently labelled holdout evaluation and adjudication remain required for accuracy claims.

See the evidence

Try the engine, then inspect the limits.

Convert a PDF in the public preview, examine the published benchmark method, or review the research program behind future accuracy decisions.

Engine assurance summary

The engine records evidence and routes uncertainty. Human release evidence remains bound to the exact published version.