Viska sjóðir · Engineering Brief

The Oracle

One machine now publishes the fund’s numbers — every figure with its source, its time, and its proof.

LIVE ON viska.gg · DECLARED 31 JULY 2026
Why it had to exist

A dashboard can lie two ways

A wrong number — or a stale number dressed as fresh. Both cost trust exactly when the fund needs it. The Oracle exists to make both impossible.

Before

Numbers assembled in many places, each with its own idea of “current”. No single answer to “where did this figure come from?”

Now

One publisher assembles the fund state. Every surface reads the same document — and the document defends itself.

The standard

A figure that cannot prove its origin is not shown. A gap is shown as a gap — never a zero, never a guess.

The concept

Sources in, truth out

Nine data streams flow in. The Oracle assembles, checks, and stamps one document. Everything the fund sees reads from it.

9 streams

  • Broker positions
  • Broker cash & flows
  • Market prices
  • Currency rates
  • …each on its own clock

The Oracle

  • Assembles one fund document
  • Runs its laws on every figure
  • Stamps source + time on each
  • Publishes gaps honestly

Surfaces

  • Dashboards
  • AI agents
  • Analysis & reports
  • …all citing the same truth
What was built

Four pieces, one discipline

01The publisher. Assembles the fund document and refuses to publish a figure it cannot defend. A refused figure states the rule that withheld it — refusal is information, not failure.
02The laws. Checks that run on every publication — holdings cannot vanish silently, no total without a live currency rate. Each law reports in both directions: a pass is evidence too.
03Völva — the clock board. A page showing when every data stream last delivered, each on its own clock. Clocks are never merged into one “last updated” — that would be a lie whenever they disagree.
04The verified deploy. The live site names the exact version it runs — and a script proves it after every release. “It should be live” was replaced by “it is proven live”.
live — a real delivery, from the live system example — a real shape from the frozen contract document, not evidence anything arrived unsound — a real value whose source is unavailable not stated — nothing claimed, shown as such
The snapshot spine

Every publication is a photograph

The Oracle does not stream opinions — it takes frozen, timestamped pictures of the fund and keeps them.

§1Every hour, a photograph. The broker book, market prices, and currency rates are read and assembled through the publication laws. Anything unverifiable is withheld with a named gap — never estimated into the picture.
§2A snapshot is immutable. The trail is never rewritten — older documents are preserved exactly as published and marked, not edited into compliance.
§3Storage is attested, not assumed. Before trusting its disk, the machine proves the disk can actually hold history. If it cannot, the Oracle refuses to run — it will not quietly forget rather than admit it.
§4The newest snapshot is what everyone sees. Every dashboard, agent, and report reads the same latest picture.
§5Every reading is re-audited. The trust verdict on a document is recomputed at the moment it is read — the mark an outside auditor would derive, not the machine grading itself.
§6A heartbeat watches it all. A public health line reports whether collection and storage are sound — carrying no fund numbers at all.
How it shipped

Reviewed like it matters

Because it does — this machine speaks for the fund’s money.

Twenty-three review rounds on the launch alone — each fix independently re-verified.
Every gate tested both ways — a check that cannot fail is not a check; each one was proven able to catch its target.
Launch declared with named limits — what is proven, and what is not yet, stated in the same breath.
Rollback rehearsed before launch — the way back was proven safe before going forward.
How it is maintained

It checks itself

Maintenance is not a person watching a screen — it is machinery that refuses to drift silently.

13

Live checks per release

Run against the real site after every deploy. All must pass before anything is declared.

9

Stream clocks

Each source stream is watched on its own clock. Staleness is displayed, not discovered later.

 honest

Truthful degradation

If a feed dies, the surface says so and shows what it still knows. It never blanks, never invents.

1

Line of rollback

One rehearsed command returns to the previous state. Recovery is a fact, not a hope.

What it enables

A foundation, not a feature

Every future surface inherits the same guarantee: numbers with provenance.

ADashboards that cannot silently mislead — built on one spine, each figure traceable to its source.
BAI agents answering live questions — grounded in the verified document, citing it, never improvising a number.
CObservability over agent work — the same clock discipline extends to watching agents run tasks, with the same honesty about what happened when.
DAnalysis with receipts — reports and research that state the age and origin of every input.
Next

The road from here

History. The document over time — so any past state can be re-read exactly as it was published.
More streams. New sources join under the same discipline: own clock, own proof, or not shown.
Agent access. A clean interface for agents to read the verified state — the ground truth for every automated answer.
Alerting. The clocks that today show staleness will tomorrow announce it.