Codex 11 — The Institutional Systems Architecture
Four pillars of capital and the twelve permanent institutional systems.
- Authority rank
- 3
- Version
- v1.0
- Adopted
- 2026-05-01
- Held by
- Stewardship Office
- System
- SYS-10
Source · docs/codices/CODEX-11-institutional-systems.md
Domain doctrine. Subordinate to Codex 1 and Codex 0. The enforceable specification of this Codex is Codex 0 Chapter 20 (the twelve systems) and Chapter 21 (institutional memory and lifecycle); this Codex holds the principle those chapters apply.
First principle
An institution is not its departments. An institution is the systems that connect those departments.
Departments change. People come and go. Technology evolves. Systems endure.
Therefore: every capability developed by Anabasis belongs to a defined institutional system, never to an isolated department. A capability that exists only inside a department dies with that department, and takes its knowledge with it.
The four pillars
Everything within Anabasis belongs to one of four pillars — the four forms of capital the institution compounds.
| Pillar | The development of | Includes |
|---|---|---|
| Human Capital | people | education, leadership, skills, careers, professional development, mentorship, capability, health, community, ethics, character, relationships |
| Intellectual Capital | knowledge | research, publications, curriculum, models, knowledge graphs, books, frameworks, methodologies, standards, indexes, patents, institutional memory |
| Financial Capital | sustainable resources | revenue, treasury, investments, pricing, capital, budgeting, endowment, cash flow, forecasting, investor relations, risk |
| Technological Capital | software | CapabilityOS, AI, automation, enterprise systems, APIs, infrastructure, analytics, security, data, integrations |
Every initiative strengthens one or more pillars.
The pillars and the eight strengths. Codex 0 §01.5 fixes eight institutional strengths, and Codex 1 Article III requires every feature to strengthen at least one of them. The pillars sit above the strengths as forms of capital; they do not replace the test and must never become a second, weaker one. Education, people, and community belong to Human Capital; knowledge and research to Intellectual; capital to Financial; technology to Technological.
Trust is not a pillar. Trust is the eighth strength and it is the condition on which all four pillars compound. Capital of every form can be accumulated and then lost in a single breach of trust. Trust is therefore tested against every pillar rather than accumulated beside them.
The twelve institutional systems
Beneath the five divisions there are twelve permanent systems. They are the backbone.
| ID | System | Holds |
|---|---|---|
| SYS-01 | Identity | authentication, profiles, organizations, permissions, roles, membership, verification, SSO, privacy |
| SYS-02 | Learning | courses, lessons, assessments, paths, adaptive learning, certifications, progress, capability scores, faculty, students |
| SYS-03 | Knowledge | research, library, publications, journals, indexes, search, the knowledge graph, institutional memory |
| SYS-04 | Business | companies, projects, client relationships, enterprise clients, advisory, strategy, consulting, organizations |
| SYS-05 | Finance | payments, subscriptions, invoices, treasury, forecasting, budgets, capital, investor reporting, revenue, expenses, taxes |
| SYS-06 | Ventures | founder profiles, applications, incubator, accelerator, mentorship, investor network, diligence, fundraising, demo days |
| SYS-07 | AI | agents, decision engine, recommendations, automation, summaries, planning, forecasting, retrieval, reasoning, workflows |
| SYS-08 | Communication | messaging, email, notifications, calendar, events, announcements, communities, groups, forums, video, meetings |
| SYS-09 | Analytics | indexes and KPIs, reporting, dashboards, usage, revenue analysis, learning analytics, forecasting, institution health |
| SYS-10 | Governance | policies, the Constitution, the Codices, the Standards, compliance, approvals, audit, ethics, decision logs, institutional history |
| SYS-11 | Operations | internal teams, hiring, payroll, projects, tasks, documentation, legal, assets, vendors |
| SYS-12 | Infrastructure | cloud, databases, storage, APIs, security mechanism, monitoring, logging, scaling, backups, disaster recovery |
Identity never belongs to one division; it belongs to the institution. The same is true of all twelve.
Systems, divisions, and engines
The three are different axes and none replaces another.
DIVISIONS own mandates and outcomes; accountable to the Executive Office
SYSTEMS own capability; permanent; cross every division
ENGINES are implementations inside a system- 1A division owns outcomes. A system owns capability. No system is owned by a division.
- 2Every Registry entry names exactly one system, in addition to its owning division.
- 3A capability needed by two divisions moves into the system that owns it. It is never built twice.
- 4The twelve are permanent and closed. A thirteenth system requires an amendment to this Codex, not a decision record.
- 5Anything that fits no system is misplaced, and is redesigned rather than filed under the nearest system.
The Capability Graph
Every person, lesson, publication, advisor, company, credential, mentor, founder, investor, goal, project, organization, and workflow is connected through one institutional graph.
Not for surveillance. For understanding. The distinction is enforced, not asserted. The graph carries three tiers of participation, specified in Codex 0 §06 and §21:
| Tier | Examples | In the graph |
|---|---|---|
| Institutional records | curriculum, publications, credentials, capabilities | always |
| Relationship records | mentorship, advisory engagement, venture participation | yes; visible only to the parties and to a role with explicit scope |
| Personal signals | AI conversations, private drafts, notes, meeting content | never — only what a person themselves publishes as an outcome |
What the graph makes possible: a person who intends to found a biotech company is told what they have already demonstrated, which prerequisites remain, which programmes and advisors are open to them, and which introductions they may request. That is institutional intelligence, and it is directed at the person's own ascent.
Institutional intelligence
The institution should become progressively wiser. Every question it learns to answer is first classified, in writing (Codex 0 §21):
- Permitted — answerable about named individuals to a role with explicit scope.
- Aggregate only — answerable above the disclosure threshold, never resolving to a named person.
- Self only — answerable to the person themselves, and to no one else without their consent.
- Refused — never answered, with the reason recorded.
Two rules govern all of them. A match between people is an offer a person may decline, never an assignment and never a disclosed ranking. And no answer to any of these questions is ever sold (Codex 1).
Institutional memory
One of the greatest risks facing any organization is forgetting why decisions were made.
Every significant decision is preserved with nine fields: decision, reasoning, alternatives considered, evidence reviewed, expected outcomes, owner, date, review schedule, result. The result is written at the review date whether or not it flatters the decision. A decision whose result is unwritten past its review date is overdue, and is listed as overdue.
Future leaders must be able to understand not only what was decided, but why. An executive in 2034 asking why the certification model changed receives the proposal, the evidence, the review, the implementation plan, the outcome metrics, and every later revision. They do not receive a transcript of anyone's private conversation. Memory is a record of institutional acts, not of personal activity.
The institutional lifecycle
Every initiative moves through the same stages.
Discover → Research → Design → Prototype → Validate → Build → Deploy
→ Measure → Improve → Standardize → Teach → Scale → Preserve
→ Retire or SupersedeStages may be short. They are never skipped. Standardize and Teach are the two most often skipped, and they are the two that make capability compound rather than repeat. Preserve means the memory-layer entry exists. Retire or Supersede exists because an institution that cannot end things accumulates until it collapses.
Prohibitions
- 1A capability built inside a department rather than a system.
- 2A forked implementation of a system for one division's convenience.
- 3One system holding another system's source of truth.
- 4A thirteenth system created for convenience rather than by amendment.
- 5Identity delegated to a division.
- 6AI becoming the system of record for anything.
- 7Personal signals — conversations, drafts, notes — entering the graph or the memory layer.
- 8Any institutional-intelligence answer that ranks named people to a third party, or that is sold.
Governing and governed
Derives from: Codex 1 (mission and non-negotiables), Codex 0 §01 (strengths and tests), §02 (divisions), §05 (engines), §06 (graph), §08 (permissions), §16 (reporting thresholds).
Specified by: Codex 0 Chapter 20 (the twelve systems, with every Registry ID assigned) and Chapter 21 (memory, the nine-field record, the lifecycle, the question classification).
Enumerated by: the Registry, SYS- class.