Help & Manual
A workflow reference for licensed professionals (PE / AIA / CCM / LS) using Shield for the first time.
Quick start
New to Shield? Do these five things in order — each links to the section that walks you through it.
Known in-flight items
Shield is actively developed. A few navigation items are mid-tidy — we note them here so nothing surprises you. None affects the integrity of your records.
- The three project surfaces (
/projects, project register, sign-off) are currently linked by a matching project-ID string rather than a shared record — keep the ID consistent across them (see section 05). - Sign-off captures projects as free-form text (no canonical project picker yet) — see section 05.
How to use this manual
AECO Shield helps you use AI tools in licensed practice without putting your stamp — or your firm — at risk. When you use an AI tool for engineering, architecture, or construction work, Shield assesses whether that tool meets professional-liability standards, flags the ones that don't, and records every decision you make. The result is a defensible audit trail: if a question ever arises — from a client, an E&O carrier, or a licensing board — you can show which tools you used, how they were vetted, and who signed off. Shield doesn't tell you not to use AI; it lets you use AI freely while keeping the evidence that you did so responsibly.
For the methodology behind this — the scoring, the standards, the calibration — see the Methodology page.
This manual covers how to use Shield's workflows — what to click, what to expect on each screen, and what to do with the result. It does not re-explain what the scores mean, what the methodology commits to, or how the platform is governed. Those live on their own pages and are cross-referenced below.
When a section says "for what X means, see the FAQ," take the link. The definition is already there, and re-writing it here would just drift over time.
Where each concept lives
- Concept definitions
- ACS score, FitScore formula, Stamp-Safe classification, the Q21b Liability Transfer Test, hard filters HF1–HF5, the D4.5 ceiling rule — /faq.
- DCS thresholds + HF rulebook
- Where the 88 / 68 GREEN / AMBER / RED thresholds come from (multi-framework convergence), and the hard-filter discipline that no commercial or customer request can override — Quality Policy §3.3 + §3.6.
- Governance + retention
- How methodology revisions are handled, how standards citations are maintained, how the 7-year artifact retention works, and how incidents are disclosed — Procedures & SOPs.
- Methodology philosophy
- The seven liability layers, the multi-framework calibration argument, and why the platform is scoped the way it is — /methodology.
- Acronym glossary
- Compact single-line definitions for every acronym on the platform (ACS, FitScore, HF1–HF5, D1–D7, L1–L7, DCS, CES, DRS, CPS, FGPI, etc.), with deep-link anchors and methodology quotes reproduced verbatim from the ACS Methodology — /help/glossary.
The eight sections cover the workflows a first-time practitioner most needs, in the order they typically come up. Skip ahead using the section index above; forward-references between sections are linkable.
Getting started
1. Create your account
Sign up at /signup with your name, work email, and a password, and choose your role:
- Licensed Professional — anyone whose work is anchored to a license (PE, AIA, CCM, LS, and related). The primary role for practitioners who stamp or take responsible charge of work.
- Buyer roles (Project Manager, Digital / BIM Manager, Pursuits, Executive) — team members who manage or support projects but don't hold the responsible-charge license.
- Tool Vendor — software or service providers submitting their tools for assessment. Vendors land on a separate vendor surface, not the buyer dashboard.
2. Confirm your email
Click the confirmation link we send to activate your account, then sign in at /login.
3. Set up your firm
Before running assessments or generating documents, complete your firm profile at /onboarding:
- Firm name — the legal entity name used on your stamps, certificates, and contracts.
- Firm email — the firm's primary contact (pre-filled from your account email; edit if different).
- Firm type — Private (commercial, residential, industrial), Public (state & local), or Public (federal); affects which regulatory citations apply.
- Firm size — 1–50, 51–200, 201–500, or 500+ staff; affects your maturity benchmark band.
- Jurisdiction (optional) — e.g., US-NY, US-CA, CA-ON; affects jurisdiction-specific citations.
- Profession track(s) — select every track you hold a license in (PE, AIA, CCM, LS). Required for licensed professionals; drives your Stamp-Safe classifications, Layer 1 responsible-charge framing, and unlocks Policy, Project Audit, and Firm Audit report generation. You can hold more than one. Sub-credentials (PE-SE, NCARB, LEED-AP, etc.) can be added later in Settings.
Once complete, you land on your dashboard with everything unlocked. You'll be guided back here automatically until it's done — the core features (Tool Check writes, report generation, sign-off) need your firm and credential set up first. To edit later: firm fields live at /settings/firm, credentials live at /settings/profile (or via the "+ Add" button on the top-bar role badge).
Signing in and where you land
Signing in drops you at /dashboard/home — the Shield home surface. There is a lot on this page, so the trick is knowing where to look first. The five zones are numbered top-to-bottom, but the reading order is not top-to-bottom — it is "attention first."
Home reading order (for daily use)
- Zone 1 — Your week + defensibility risk. The left panel (My Week) surfaces the tasks needing your action right now. The right panel (Defensibility Risk Grid) shows tool count, active project count, and the tools registered across your projects.
- Zone 1.5 — Project AI Status. Cards render only for projects needing attention (ACTION + AMBER). GREEN projects collapse into a "+ N all clear" summary line. If you see no cards and only an all-clear line, nothing needs you right now.
- Zone 4 — Workflows. Skip past Zones 2 and 3 for now (firm posture trajectory and maturity band — read on a longer cadence, not daily). Zone 4 is your task-starting menu: eight workflow rows, each with a + New button pointing at the right entry surface.
- Once you have the pulse of the day, come back for Zones 2 and 3 for context, and Zone 5 for the recent activity ledger.
The TopBar
Right side of the top bar, in reading order:
- Firm label — a non-interactive chip showing your active firm name. If you belong to more than one firm, the chip reflects the one you are signed into.
- Defensibility badge — a colored shield + status word (Strong / Developing / At Risk / Not Assessed). Click through opens the Firm Audit Report. Section 07 (later batch) covers the honest-signal rules — the badge does not go green just because you have no projects.
- Notification bell — aggregates My Week attention items, a methodology-current chip, and (for admins) Standards Watch updates. Active glow means something is waiting for you.
- Feedback — email link to feedback@aeco.digital.
- Role menu — profile, firm settings, sign out.
The Sidebar
Seven journey-ordered groups, top-to-bottom:
- Today — Dashboard, Action Items. Your daily start. /action-items is the standalone attention page — the same items that appear in Zone 1's My Week, on a dedicated screen.
- Assess a Tool — Tool Check, Tool Assessments (your firm's history of runs — see section 10), Compare Tools, US Market Readiness (see section 03.5), Suggest a Tool, Registry. Not sure which surface to use? See section 01.5.
- Project Work — Projects, Project Register, Project Sign-Off.
- Firm Setup — Digital Maturity (the FMP self-assessment — see section 04).
- Evidence & Audit — Executive Briefing (capstone cross-domain report), Firm Audit Report, Project Audit Report, Governance Certificate, Audit Trail, AI Usage Log.
- Governance Docs — AI Policy & SOP, Training Matrix, Gap Report, Report Shadow AI Use.
- Reference — Methodology, Reports (the unified register of everything you or the platform has generated — see section 10).
Admins also see a Admin group at the bottom (Standards Watch); it's hidden for non-admins. Cross-platform switching (Shield / Bid & Intelligence / Strategic / Career) is via the top-bar app switcher, not the sidebar.
First 5 minutes
- Check My Week for tasks needing you today.
- Check the Defensibility badge — the colored shield in the TopBar.
- Scan Zone 1.5 for projects that need attention.
- If Zone 1.5 is empty and the badge is green, come back at the end of the day for the activity ledger (Zone 5).
- If anything is amber or red, that is your next click.
Three tool surfaces — which do I use?
Shield has three tool-related surfaces that get conflated. Pick by the question you’re trying to answer.
/vendor-dashboard and this buyer manual doesn’t cover it.A fourth thing that sounds similar but isn't
Running a Tool Check
A Tool Check is a private compliance assessment of an AI tool against your project's discipline and your professional track. It stays in your dashboard — it does not publish to the public registry. For what an ACS score, Stamp-Safe classification, or Go / No-Go signal actually mean, see the FAQ. This section covers how to run one.
Step 1 — Open the picker
Sidebar → Tool Check (or from the home page, Zone 4 → Tool Check → + New). You land at /tool-check — a searchable catalog of every tool in the registry.
Step 2 — Pick your project type
Before running the check, pick the project discipline (Building / Bridge / Transport / Rail / Mixed) from the chip row at the top of the picker. This matters: some compliance questions apply only to certain disciplines, and the scanner filters questions whose discipline_scope excludes your project type. Picking "Building" for a bridge audit will surface the wrong question set.
Step 3 — Find the tool (or request one)
Search the catalog by tool name, vendor, or workflow category. Each row shows tool name, vendor, verified badge (if applicable), category, pricing model, and assessment status. Click Run check → to start.
Tool not in the catalog? The banner at the top of the page — "Tool not listed? — Request an assessment →" — routes to /contact for an editorial-team assessment. Typical turnaround is a few business days.
Step 4 — Answer the compliance questions
The scanner walks you through up to 22 layered questions (L1 Responsible Charge through L7 Vendor Transparency), filtered by your discipline and profession track. The top bar shows a "Private draft" amber pill the whole time — this assessment is yours, not the vendor's audit-of-record.
Your profession track (PE / AIA / CCM / LS) is snapshotted at draft creation. Updating your credentials mid-assessment does not shift the visible question set for that draft.
Step 5 — Submit and view result
On submit you return to /tool-check with a green banner: "Assessment submitted — [tool] has been scored: ACS X.X." Click View result → to open the result page (section 03).
Scoring is asynchronous. If you hit the banner before scoring lands, the copy switches to "submitted and is being scored — refresh in a moment to see your ACS result." Refresh; do not re-submit.
Tool Check checklist
- Sidebar → Tool Check.
- Pick your project type (chip row).
- Search + pick a tool, or request one via the banner.
- Answer the questions (up to 22, filtered).
- Submit — refresh if scoring is still in flight.
- Click View result → section 03.
Reading the score screen
The result page (/tool-check/[id]) renders in one of four states depending on where your assessment landed. What each score means as a concept is at the FAQ; this section covers what you see, what to do next, and one important optical detail.
The four states
| State | What you see | Action |
|---|---|---|
| Draft | Muted clock icon, "Draft in progress" | Resume tool check |
| Incomplete | Amber warning, "Scoring didn't complete" | Re-run scoring |
| Clear | Green banner, full 4-card grid + layer alignment | Read the grid and decide |
| Blocked | Red banner, HF flags rendered first, greyed ring | Do not proceed — see section 08 |
CLEAR state — what the grid shows
Green banner at the top: "Scored — hard filters clear." Below it, a 4-card grid:
- ACS ring — circular gauge colored by score, with the band label underneath (e.g. "High Confidence").
- Stamp-Safe pill — Stamp Supporting (green) / Conditional (muted) / Not Stamp Safe (red).
- Go / No-Go — Approved (green) / Conditional (amber) / Insufficient for Stamped Work (red). The red pill used to read "Do Not Use"; the label was scoped honestly in 2026-07 — the verdict is about stamped work, not the tool's fitness for any use.
- Compliance Exposure — Low / Moderate / Elevated / High with the numeric score. Hover reveals the breakdown:
ACS X · flags Y · L1 Z · ins W.
Below the grid, the Layer Alignment section renders one filled bar per liability layer (L1 Responsible Charge through L7 Vendor Transparency), with the aggregate alignment score on the right. Each bar's color tracks its individual layer score, so you can see at a glance which layer is dragging the composite down.
BLOCKED state — the important optical detail
If a hard filter fires (HF1 through HF5 — the rulebook is in Quality Policy §3.6), the screen reorganizes. Red banner at the top, hard-filter flags list rendered before the score grid, and the ACS ring in the grid is neutralized grey with a "DOES NOT CLEAR" caption underneath.
This is deliberate. A tool that fails a hard filter can still have a numerically respectable composite ACS — a 6.0 blocked on HF3 (E&O coverage below required threshold) is a hard "no" regardless of its Moderate ACS band. The grey ring and DOES NOT CLEAR caption are the optical guardrail. Without them, the eye reads 6.0 / Moderate as a pass. It is not.
What to do with the result
- Go / No-Go = Approved. Proceed. If you plan to register this tool on a project, that workflow is in section 05.
- Go / No-Go = Escalate. Read the Layer Alignment section — the specific low-scoring layer usually tells you what to raise with the vendor or your practice lead. Section 08 covers the escalation path.
- Go / No-Go = Insufficient for Stamped Work (or blocked state). The score screen and the Insufficient- for-Stamped-Work screen are the same screen. Section 08 covers what to do next — the platform does not offer an in-app override.
One thing to notice
The result page is read-only. There is no save / discard / export button here. Registering this tool onto a specific project (so it counts toward that project's audit and register) is a separate workflow — section 05.
Evaluating US Market Readiness
US Market Readiness is a per-tool lens that applies the ACS hard filters (HF1–HF5) as US procurement requirements and returns a verdict: US-Ready, Conditional, or Not US-Ready. Alongside the verdict you get a 51-state licensure coverage grid (all 50 states + DC) and a per-check requirements list — for each HF that's missing or partial, exactly what the tool would need to disclose or do to clear US procurement.
It exists because your ACS Tool Check score answers "is this tool defensible for your discipline and risk?" — but a US buyer evaluating an international vendor also needs the answer to "does this tool meet the baseline any US firm would check for?" The two questions have the same underlying fields (licensure states, E&O + GL insurance, DBE capacity, certifications) but different framings. US Market Readiness is the second framing.
Where it lives
Sidebar → Assess a Tool → US Market Readiness. The page opens with a searchable picker of every Registry-published tool. Pick one and its verdict, state grid, and HF1–HF5 compliance checks render below. The selected tool syncs to the URL (?tool=<id>) so refreshes and share-links carry your selection.
Missing data is a signal, not a bug
A tool with undisclosed licensure states or insurance renders as Not US-Ready with BLOCK-status checks that say "vendor has not disclosed X". This is informative, not an error. It tells a US buyer exactly what an (often international) vendor must disclose for procurement to proceed — the picker deliberately includes tools that fail HF1–HF5 because those are precisely the tools whose gap you need to see before you can decide.
Distinct from Tool Check
Tool Check (sections 02–03) runs your firm's own private ACS assessment against a tool for your discipline and risk profile — it's YOUR firm's scoring cycle, private to your dashboard. US Market Readiness reads the PUBLIC Registry-published assessment data (the vendor's scored+published ACS row) and re-renders it through a US-market lens. They're complementary: Tool Check is your own scoring, US Market Readiness is the vendor's public score seen through a different frame.
If a tool isn't in the picker
Only Registry-published tools appear (assessment_status=published + public_registry_visible=true). If a tool you care about isn't listed, its vendor hasn't completed an assessment and passed editorial review yet. Vendors can get listed via /contact (self-serve vendor tier or the higher-touch US Market Entry package for international vendors).
Completing the Digital Maturity Assessment
The Firm Maturity Profile (FMP) is a self-assessment of your firm's readiness to use AI responsibly across seven dimensions of digital practice. It takes 10–15 minutes. For what the score bands mean and how the composite is computed, see the FAQ; this section covers how to run it and what the result unlocks.
Where to start
From the home page, Zone 3 (Firm maturity · methodology-stamped band) shows your calibrated band + the date the next reassessment is due. Click "View full maturity report →" to open the full report at /maturity/progress — that is the primary entry point on the buyer surface today, and it is where you start (or re-start) an assessment.
What the assessment covers
A short firm-info step (primary discipline / firm type / firm size band) opens the wizard, then it walks you through seven scored dimensions: D1 Data, D2 BIM & Digital (with a D2b ISO 19650 sub-dimension), D3 AI Readiness, D4 Process & Governance, D5 Talent & Capability, D6 Adoption & Scaling, and D7 Supply Chain. About 40 questions total.
What each dimension measures and how the composite is scored is at the FAQ under Digital Maturity Assessment. Most questions are 1–5 Likert with plain-English options; D2 shows rubric anchors at levels 1, 3, and 5 to help you calibrate; D2b and D7 mix booleans, Likerts, and short enums.
The D4.5 ceiling — read this before answering D4
D4.5 asks whether your firm has a named independent reviewer of AI-assisted work before a licensed-professional stamp goes on it. If the answer is no, your D4 Process & Governance score is capped at 4.9 (Developing) — no matter how strong your other D4 answers are.
This is a deliberate governance gate, not a bug. Answering yes-when-you-should-say-no does not raise the score in the long run — the moment an audit walks the actual review process, the absence gets flagged. If you land on a "stuck at Developing" band, D4.5 is usually why, and it is the fastest single improvement to make.
What the FMP unlocks
The band is not just a badge; it drives three downstream signals:
- Home dashboard. Zone 3 shows your calibrated band, when it was last calibrated, and firm-size context. Without an FMP the panel stays empty.
- FitScore comparisons. MaturityMatch is a component of FitScore (see FAQ). Without an FMP, tool comparisons cannot weigh whether your firm is ready to govern the tool — a highly-scored tool is only useful if your firm can handle it.
- Firm Audit + Defensibility. Coverage-gap analysis in the Firm Audit Report (section 06) compares per-project E&O requirements against firm capacity from your latest FMP. Without one, the coverage arithmetic cannot run.
Reviewing past assessments
Every assessment you've completed is openable:
- On the Maturity Progress page (
/maturity/progress), the Assessment History table lists all your assessments. - Click any row to open its full detail — the radar, per-dimension scores + peer comparison, and priority gap report for that specific assessment.
- You can export the KPI report for any past assessment, not just the latest — the export button lives on the detail view.
Correcting a mistaken assessment
If you complete an assessment with wrong answers, you can void it:
- Open the assessment from your Assessment History (on the Maturity Progress page) or from Reports.
- Click "Void this assessment" and confirm (add an optional reason for the audit trail).
What voiding does:
- The assessment is excluded from your current maturity band, trends, benchmarks, certificate eligibility, and reports.
- It stays in your history, clearly marked as voided, so your audit trail remains complete.
- Your maturity band reverts to your previous valid assessment (or to "not yet assessed" if it was your only one).
Voiding is one-way — to correct a wrongful void, complete a new assessment.
Digital Maturity checklist
- Home page → Zone 3 → open the assessment (URL note above notwithstanding).
- Answer the firm-info step (discipline / type / size band).
- Walk D1 → D7 (~40 questions, 10–15 minutes).
- At D4.5, answer honestly — a "no" caps D4 at Developing regardless of other answers.
- Submit.
- Confirm the calibrated band appears in Zone 3 of the home dashboard.
Registering tools on projects + signing off
Once you have run a Tool Check (sections 02–03) and the tool is approved for use, there are two related workflows: registering the tool on a specific project (so it counts toward that project's inventory), and signing off on the project's AI usage at a checkpoint (so a named professional carries the responsibility). This section covers both — and one important honesty note before you start.
Read this before you begin
Shield currently has three project surfaces that share a project by ID string, not by a single shared record:
/projects— the canonical project register (schema-backed projects with type, phase, and status)./dashboard/project-register— the per-project AI-tool inventory (which tools are active, blocked, or archived on each project)./dashboard/sign-off— the sign-off ceremony (currently uses free-form project ID fields; no canonical picker there yet).
Use the same project-ID string across all three. That string is what glues them together right now. If you type PRJ-2026-Healthcare-DB in the sign-off but the register says Healthcare Data Center 2026, the two will not correlate on your dashboard even though they refer to the same job.
These surfaces are being brought into tighter coupling. For now, project-ID string consistency is the practitioner's responsibility.
Project Register — the per-project AI-tool inventory
Sidebar → Workflows → Project Register (/dashboard/project-register). Four-step flow:
- Pick a project. Three options in the picker: a dropdown of projects that already have sign-off events, a dropdown of canonical projects from
/projects, or type a new project ID + display name. Use whichever matches your other surfaces — see the callout above. - Manage the tool inventory. A table shows each tool + category + ACS band + FitScore + status. Use + Add Tool to add a tool from the catalog and set its status: Active in use, Archived from project, or Blocked from use. Change a status inline; archive a row with the row action.
- Generate the Register PDF (optional but recommended before external review). The PDF aggregates the current inventory, a snapshot of ACS / FitScore per tool, sign-off count on file, and a methodology stamp. Generation runs ~20–40 seconds.
- Download the PDF from the completion panel. Download link expires in 24 hours; the generation itself is recorded in the audit trail.
Project Sign-Off — the liability-holder step
Sidebar → Workflows → Project Sign-Off (/dashboard/sign-off). Four-step flow:
- Identify the project. Three free-form fields: Project ID (mono), Project name (display), Signer display name (prefilled from your most recent prior sign-off, if any). Use the same project ID string you used in Project Register.
- Confirm. The next screen shows the project + signer + a red-bordered legal assertion: "By confirming sign-off, you assert professional responsibility for all AI tool usage on this project as captured in the AI Usage Log at the moment of confirmation. This receipt is an evidentiary record." Type your account password to confirm.
- Receipt generated. The completion panel shows Receipt ID, Project, Signer, Confirmed-at timestamp, AI events captured (the count of usage events snapshotted into this receipt), and methodology version. Click Download Receipt PDF ↓.
- The download link expires in 24 hours. The receipt is also indexed in the AI Usage Log at /dashboard/audit-log with event type
sign-off-confirmed. You can retrieve it any time within the 7-year retention window.
A note on methodology versions. Receipts are stamped with the methodology version in force at the moment of sign-off — so a receipt signed under v3.3 stays stamped v3.3, and a receipt signed under v3.4 stays v3.4. Both are valid as-stamped. Historical stamps are preserved, never rewritten; if you see "v3.3" on an older receipt, it is not stale — it is a faithful record of the methodology under which the sign-off happened.
Why sign-offs matter
The sign-off is the moment your firm's AI activity becomes a defensible record. Everything before it is what happened; the sign-off is a named professional saying, "as of this timestamp, I take responsibility for that activity under my license." If an E&O carrier, client, or licensing board ever asks "who was responsible for the AI work on that project on that date," the receipt is the answer. Missing sign-offs are the single largest hole an audit review will find.
Register + Sign-Off checklist
- Pick your project ID string — write it down. Use it verbatim on every surface.
- Open Project Register — add the tools you use on this project, set status (active / blocked / archived).
- Generate the Register PDF (optional; useful before review).
- Open Project Sign-Off — enter the same project ID string + name + signer.
- Read the legal assertion. Confirm with your password.
- Download the receipt PDF within 24 hours.
- Find it later in the AI Usage Log.
Generating the Firm Audit Report
The Firm Audit Report aggregates your active projects' Compliance Exposure Scores (CES) into a single insurer-format PDF. It is the artifact you would hand to an E&O carrier during a renewal conversation, or reference if a claim ever arose. The Defensibility badge in your TopBar (section 07) is the always-visible glance version of the same underlying signal — this report is the full paper.
Where to start
Sidebar → Workflows → Firm Audit Report (/dashboard/firm-audit-report), or click the Defensibility badge in the TopBar.
Prerequisite: a completed Firm Maturity Profile (section 04). Without an FMP, the coverage-gap arithmetic in Signal 1 has no firm-capacity input to compare against and cannot run.
Read the three disclosure blocks first
Before the "Begin" button, the page shows three left-bordered blocks. Do not skip them — they define the shape of the numbers you are about to generate:
- Methodology stamp (blue). The section of the AECO Shield methodology this report is built against. This is the citation you would give if asked "where does this analysis come from."
- FGPI labeling (amber). The Firm Governance Prioritization Index is a governance prioritization indicator, not a present-value liability total, not an actuarial expected-loss estimate, and not an insurance pricing input. Read this carefully — it tells you what the number means and, as importantly, what it does not mean.
- Heuristic calibration disclosure (orange). The calibration constants (base claim rate, hazard multipliers, project-type and jurisdiction factors) are author-selected defaults informed by industry observations, not empirically validated actuarial parameters. The ±% sensitivity band on the probabilistic signal reflects this uncertainty.
Running the flow
- Click Begin →. The confirm panel lists what will be generated (per-project CES + band distribution + max-CES + coverage-gap analysis + methodology grounding).
- Click Generate Report. Generation takes 5–30 seconds (portfolio aggregation + PDF render). Do not close the tab.
- The complete panel shows Report ID / Generated timestamp / Projects assessed / Projects skipped / Worst-project CES / Methodology version, followed by the Portfolio Rollup + Dollar Exposure section described below.
- Click Download Audit Report PDF ↓. Download link expires in 24 hours; the generation is indexed in the audit log with event type
firm-audit-generated.
Reading the result — four numbers to know
- Worst-project CES (maxCES). Your single most-exposed project's CES score, band, and project name. Plain reading: if a claim happens, this is where it is most likely to happen. This is also the signal that drives your Defensibility badge's color (section 07) — badge and report agree by construction.
- Signal 1 — Coverage Adequacy Gap (deterministic). The dollar difference between your active projects' aggregate E&O requirements and your firm's current E&O capacity (from your latest FMP). A positive number is a shortfall — money you would owe if a claim hit and coverage was inadequate. Deterministic arithmetic, not a model — no calibration uncertainty here.
- Signal 2 — Portfolio Expected Liability (probabilistic). An annualized expected-liability indicator across your active portfolio, with a ±% sensitivity band. Read: "in an average year, this is the exposure our tool choices carry." The sensitivity band tells you how much to distrust the exact number — the wider the band, the more caveats.
- FGPI (Firm Governance Prioritization Index). Signal 1 + Signal 2 combined into a single index, for leadership to prioritize governance work across the portfolio. Not a valuation, not a premium input, not a claim reserve. The mandatory labels rendered under FGPI repeat what it is not — so a downstream reader cannot misuse it.
Below the four numbers, a per-project expected-loss table shows each project's fee-proxy + hazard multiplier + type factor + jurisdiction factor + resulting expected loss. That is where you look to see which projects are driving Signal 2, if you need to prioritize remediation. For the full formula, see /methodology §9 (portfolio rollup + dollar exposure appendix).
Firm Audit Report checklist
- Sidebar → Workflows → Firm Audit Report.
- Read the three disclosure blocks — especially the FGPI labeling. They tell you what the numbers are for.
- Begin → confirm → generate (5–30s).
- In the complete panel, note maxCES first (worst project), then Signal 1 (coverage gap in dollars), Signal 2 (portfolio expected liability + sensitivity band), and FGPI (composite).
- Download the PDF within 24 hours.
Reading the Defensibility badge
The Defensibility badge sits in your TopBar on every authenticated page — a colored shield icon, the eyebrow DEFENSIBILITY, and a status label. It is the always-visible glance version of the Firm Audit Report (section 06). Click it to open the full report.
The four states
| Color | Label | Icon | Plain meaning |
|---|---|---|---|
| Green | Strong | ShieldCheck | Your worst-project CES is in the Low band. Strong defensibility posture. |
| Amber | Developing | ShieldHalf | Your worst-project CES is Moderate. Meaningful room for improvement. |
| Red | At Risk | ShieldAlert | Your worst-project CES is Elevated or High. Address the worst project first. |
| Gray | Not Assessed | ShieldOff | No projects assessed yet — the signal is not defensible, just unknown. |
The honesty rules — why the badge is trustworthy
The badge is designed so its green state means something. Three rules make this true:
- Empty portfolio → GRAY, never green. If your firm has no assessed projects, the badge shows Not Assessed — not Strong. A firm with zero projects on file is not defensible; it is unknown. The badge tells you the truth.
- Color comes from your worst-project CES. The badge does not average across your portfolio; it inherits the band of your worst project. Your defensibility is only as strong as your most-exposed exposure.
- Coverage-fraction downgrade. If fewer than half your projects have been assessed, the badge drops one band (Green → Amber, Amber → Red). You cannot claim Strong defensibility while flying blind on half your portfolio. Getting more projects assessed lifts the ceiling back.
The hover tooltip
Hover the badge to see: the status label, your worst project (name + CES + band), the assessed count (N of total), the insurance coverage gap in dollars, and a short disclaimer ("Indicative only — not legal/professional advice. Verify coverage with your carrier."). Clicking the badge opens the Firm Audit Report (section 06).
One thing to notice
The badge deliberately hides when the signal cannot be computed — for curator/admin accounts with no firm, or if the underlying data fetch fails. If you do not see the badge in your TopBar, it is hidden by design; it is not silently showing you a false Strong.
When Shield says a tool is Insufficient for Stamped Work
A Tool Check can come back with a verdict of Insufficient for Stamped Work in one of two shapes, and it's worth naming them separately:
- Blocked — a red banner, a grey ACS ring, and one or more
HFxhard-filter flags. This means the tool failed at least one hard filter (see Quality Policy §3.6 for the HF rulebook). HF1 in particular is labeled Do Not Procure — an unlicensed-for-jurisdiction tool genuinely cannot be procured for that project. - Insufficient — no HF flag fired, but the final ACS score is below 6.0. The Go/No-Go pill reads Insufficient for Stamped Work (this used to read "Do Not Use" before the label was scoped honestly). The tool is not defensible for professionally-stamped deliverables at this compliance level.
Scope, said plainly: the assessment is about stamped work — permit applications, sealed drawings, PE- / AIA- / CCM- / LS-signed deliverables. Non-stamped use of the tool (exploration, unstamped drafts, learning) is out of scope of the assessment. Your firm may still have policies about non-stamped use (bank-your-own guardrails); that's not Shield's call. What Shield is telling you is what its assessment indicates — that the tool falls below the stamp-safe threshold in its current compliance state. Shield is not making the stamp decision for you; that remains with the licensed signatory.
Either way — Blocked or Insufficient — the screen states the verdict. What it does not do is tell you what to do next. That is what this section is for.
Step 0 — read the specific flag, not just the red banner
Every HFx flag has a message that names exactly why the tool did not clear. A flag like "HF3 — Vendor E&O coverage below required threshold ($X vs $Y)" is a very different problem from "HF1 — Tool does not cover [state] jurisdiction." Read the specific message first — the escalation path depends on which hard filter fired. HF1/HF2 are about scope; HF3/HF4 are about the vendor's coverage; HF5 is a public-project specific requirement. The flag message names the exact delta you would need to close.
What NOT to do
Do not proceed on the strength of a "the composite ACS still looks fine" read of the score grid. A blocked tool with a 6.0 ACS is still blocked. The grey ring and DOES NOT CLEAR caption are the app's way of saying the number is informational only in the presence of a hard filter. Do not treat the number as a pass; treat it as context.
The escalation path
Shield has no in-app override or escalation queue. The actual escalation is a mix of in-app documentation and out-of-app professional judgment, in this order:
- Mark the tool BLOCKED for the project. Open Project Register (/dashboard/project-register), pick the project, and set the tool's status to Blocked from use. This records the decision in the per-project inventory and prevents ambiguity on later reviews. This is the single most important step — an unrecorded "we decided not to use it" is exactly what an audit will question.
- Generate a Gap Report. Sidebar → Workflows → Gap Report (/dashboard/gap-report/generate). This documents the compliance gap the tool would have introduced, with cited standards. If you ever need to explain why you did not use it, this is the artifact.
- Escalate outside the app. Where you escalate depends on which flag fired:
- HF3 (E&O below threshold) or HF4 (GL below threshold): your practice lead + your firm's E&O carrier. Coverage-implicated blocks are a governance conversation, not just a tool conversation.
- HF1 (jurisdiction) or HF2 (discipline scope): your practice lead. If the tool is otherwise valuable, this is a scope conversation with the vendor.
- HF5 (public-project requirement): your practice lead + procurement or contract-compliance for the affected project.
- Methodology questions ("is this the right rule?"): the methodology owner — support@aeco.digital.
- If you think the block is a data error, tell editorial. If the flag references, say, an E&O threshold you know the vendor recently raised, or a jurisdiction list you know has been updated, /contact the editorial team so the tool assessment can be reviewed. Do this instead of overriding — a corrected assessment fixes the issue for every firm, not just yours.
- Confirm the audit trail captured it. Open /audit-trail and confirm the assessment record is present. That record is your evidence, later, that you ran the check and honored the verdict.
Can you override?
Honest answer: Shield has no override flow. A blocked tool stays blocked in Shield. If you choose to proceed with the tool despite the block, that is a professional judgment made outside Shield — under your license, on your responsibility, with your own documentation.
Shield's job is to flag and record. The licensed professional owns the final call and its documentation. If you do proceed anyway, the Gap Report you generated in step 2 above is your written statement of the risk, and your practice lead / carrier consultation is the approval trail. Shield will still show the tool as blocked on the project register; that is not a bug, it is an accurate record of the methodology's verdict.
Why this matters
Every hard-filter block is a moment where the platform recorded a warning and you responded to it — regardless of which way you responded. That record is protective. If a claim later arises, the presence of a checked-and-considered flag (with either a marked-as-blocked status or a Gap Report + documented external override) is a stronger defensive position than an unchecked tool that happened to fail silently. Do not let a block go untracked.
Escalation checklist
- Read the specific HFx flag message (not just the red banner).
- Open Project Register → set the tool to Blocked from use for that project.
- Generate a Gap Report to document the compliance gap.
- Escalate to your practice lead (and E&O carrier for HF3/HF4).
- If you believe the block is a data error, contact editorial via /contact instead of overriding.
- Confirm the assessment is in /audit-trail.
- If you proceed anyway, do so under your license, with your own documentation. Shield records the verdict; you own the call.
The Certificate of AI Governance
The Certificate of AI Governance is an informational record — a methodology-stamped PDF that summarizes the AI governance practices your firm has implemented under AECO Shield as of a specific date. It draws on your Firm Maturity Profile, your sign-off receipts, your active Project Register, your Defensibility Badge state, and your Firm Audit substrate (see section 06). It is generated on demand from your firm's current state and downloadable from the dashboard.
The document reads as a descriptive record — it says "this firm has implemented the following practices as of this date" — not as a formal attestation, warranty, or legal opinion. The framing is deliberate, and important; the next Callout explains what the certificate is not.
Informational — Not For Formal Submittal
The certificate is a self-service summary of your firm's AI-governance state for your internal information only. It has not undergone independent legal review.
It is NOT legal or professional advice, NOT insurance, NOT a warranty of any tool or outcome, and NOT a substitute for consultation with your E&O carrier or counsel.
It records implementation of tracked practices as of the issue date — not any liability outcome, future compliance, or regulatory approval. Responsibility for professional judgments remains with the licensed professional under whose responsible charge decisions are made.
How to qualify
The certificate page runs a real-time eligibility check against your firm's current state before it will generate anything. Five conditions must be met:
- A current Firm Maturity Profile is on file (completed, not expired). See section 04 for how to complete one.
- At least one project sign-off receipt in the last 12 months. See section 05 for how to sign off.
- No tool currently active in your Project Register is classified Not Stamp-Safe. If one is, block or archive it before proceeding (section 08).
- No tool currently active in your Project Register is blocked by a hard filter. Same resolution path — block or archive.
- Your Defensibility Badge is Strong or Developing — not At Risk or Not Assessed. See section 07 for the badge rules.
If a condition is not met, the eligibility panel shows exactly which one and what to do about it. Fix the condition and reload the page — eligibility is checked in real time from your current firm state.
How to generate
Sidebar → Workflows → Governance Certificate (/dashboard/certificate). The page opens with:
- The prominent informational-only disclaimer at the top — read it before proceeding.
- The eligibility panel — green "your firm qualifies" with a summary of the five conditions, or a muted panel listing what is missing.
- If eligible: the generator with a Begin → button leading to a confirmation panel that restates the informational framing, then Generate certificate runs the render.
- Generation takes about 5–20 seconds (PDF render). The completion panel shows the Certificate ID, issued date, the 12-month state-through date, and a Download certificate PDF ↓ button.
- The PDF is also stored under your firm's private artifacts and appears in the "Your certificates" list at the bottom of the page for later reference.
The download link on the completion panel expires in 24 hours. To re-download a certificate later, reissue it — this generates a fresh methodology-stamped record of your current state. Historical certificates remain preserved in the list; they are never rewritten (same immutability doctrine that applies to sign-off receipts and audit records).
Point-in-time framing
Every certificate records your firm's state at a specific moment under a specific methodology version. It carries a 12-month state-through date on the PDF. If any qualifying condition ceases to be true before that date, the certificate remains valid as-issued (a faithful snapshot of the moment it was written) — it is superseded by any reissued certificate reflecting your current state. Reissue any time to snapshot your firm's current governance posture.
In-flight — informational-only for now
The certificate is currently a self-service informational record for internal use. A formal, legally-reviewed, publicly-verifiable version — with an independent verify URL and lifecycle-status tracking — is planned but not yet available. Use the current version for your firm's records, an E&O conversation, or an internal review cycle. Do not use it for a formal legal or regulatory submittal until the public-verify version ships.
Finding your work
Everything you create in Shield is saved and findable — you never lose an assessment or a generated document. Three surfaces cover the full picture:
- Tool Assessments (sidebar → "Assess a Tool", or the N records → link on your dashboard Tool Check tile —
/tool-check/assessments) lists every Tool Check your firm has run, most recent first, with each tool's ACS score, Stamp-Safe classification, and Go / No-Go signal. Click any row to reopen its full result. Re-assessing a tool creates a new record — earlier assessments are never overwritten and remain here indefinitely, so you keep the full history. - Reports (sidebar → "Reference" —
/reports) is your firm's complete register of generated artifacts — policies, training matrices, gap reports, project and firm audit reports, project registers, executive briefings, sign-off receipts, governance certificates, and maturity reports. Each is re-downloadable (clicking Open generates a fresh secure link — maturity reports open the assessment detail view where a per-FMP KPI export is available). Use the filter chips at the top to narrow to one type. - On your dashboard: Recent activity (Zone 5, lower on the page) shows a running log of what you've done — completed assessments, sign-offs, generated documents — with a methodology-code chip on each row. My Week (Zone 1, near the top) shows what's due (upcoming reassessments, calibration drift, unfinished drafts), not what you've completed — so it's normal for it to read "All caught up" right after you finish something. Look to Recent activity or Reports for the trailing record.
Quick reference
- Tool Check history →
/tool-check/assessments - All generated documents →
/reports - Raw event log (every state-changing action) →
/audit-trail - Recent activity on the dashboard → Zone 5 (dashboard home)
- What's due → Zone 1 My Week (dashboard home)