Projects don't fail at the build. They fail at "that's not what we agreed."
Discovery · Approved baseline · A record that answers with you
Clients are writing performance terms into AI contracts, and boards are asking for measured impact instead of pilots. Several of the largest advisory firms now say a meaningful share of their fees is tied to results rather than hours.
An arrangement like that needs one thing before it can exist. The outcome, written down in numbers and agreed by both sides, before the work starts.
Requirements live in decks, documents, and email threads. Six weeks in, the scope conversation starts. Reconstructing who approved what, and when, burns senior hours and goodwill. The build team inherits ambiguity. The budget inherits rework.
AI programs raise the stakes. RAND reports that by some estimates more than 80% of AI projects fail, roughly twice the rate of information technology projects that do not involve AI. That figure comes from interviews with 65 practitioners, so read it as most of them rather than as a measured rate. Gartner forecasts worldwide AI spending of $2.59 trillion in 2026. Almost none of it is protected by a document anyone can check.
All parties sign the measurable definition of done.
Server-numbered versions with permanent requirement IDs. "What changed since v1.2" is one click, answered requirement by requirement, not from memory.
A gate is a named decision on a fixed baseline. Name it what your method calls it: Discovery Complete, Design Baseline, Go-Live. The record stores its own readiness at that moment, gaps and warnings named, and nothing reads Approved while a sign-off is pending. One click builds the committee packet: the diff, the sign-offs, the fingerprint.
Every export carries version, status, approvals, and the revision record on the cover. Three artifacts add a SHA-256 fingerprint of the exact baseline with its recipe printed on the page: the client report, the gate packet, and the implementation package. The document arrives with its own receipts.
ReqPub doesn't write requirements and doesn't replace the people who do. It converts their judgment into a record that holds up.
Trackers govern activity: milestones, status, dashboards. They are good at it, and we build none of it. No Gantt, no RAG rollups, no portfolio dashboards. On purpose.
What a tracker cannot own is what "done" means: requirements with fit criteria, decisions with owners, baselines with named sign-offs. That is the record. It feeds your tracker and your build tools, and there is nothing to migrate.
A gate review on a dashboard is a meeting. A gate on a fingerprinted baseline is evidence.
The same holds beside an AI implementation team, including a vendor's forward-deployed engineers. When the work includes an AI system, the record carries the acceptance table the client signs: dimension, metric, threshold. The build team consumes requirements.json on day one. The client signs the number that stops the meter, before the meter starts.
The people who approve the work are the busiest people on it. Reviewers open a link, comment in thread, and approve on the record. No accounts, no new software. Their name and timestamp travel with the requirement from that day forward.
Scope moves. That's the job. What matters is whether the record moved with it. Every addition, edit, and cut is diffed between baselines and tied to a named approval. The next scope conversation starts from the approved record, not the email archive.
One click on an approved baseline produces the artifacts. The client baseline report: the executive summary, the client-safe brief, the revision record, behind a designed cover. Only what a published brief may contain. Internal fields are absent, not hidden.
The implementation package holds five things. requirements.json, carrying every requirement's permanent ID, statement, fit criterion, priority, and origin. The signed acceptance thresholds, each anchored to a named eval set. The acceptance checklist. The exact diff since the last baseline. The full document.
The SOW exhibit: the acceptance baseline formatted to attach to a statement of work. The acceptance table, the requirements with fit criteria, the recorded sign-offs, blank lines for the exhibit letter and the agreement date, and the verification recipe. Counsel fills in the contract references. The record supplies everything else.
The same SHA-256 sits on all of them. The document the client signed, the exhibit attached to the contract, and the package the builders received are provably the same baseline.
One sentence. ReqPub is where the client signs a measurable definition of done for an AI or technology program, a fingerprinted baseline the engineers build against, so the scope conversation six weeks in starts from the record.
One paragraph. When the builders start fast and the definition of success is still vague, ReqPub fixes the artifact, not the meeting. Requirements get measurable fit criteria and priorities. The client approves by link, with a name and a timestamp on every sign-off. The baseline gets a fingerprint. The engineers get requirements.json and an acceptance checklist on day one. The client gets a report, and the contract gets an exhibit, that carry the same fingerprint. It is not a tracker and it does not replace program tools. It is the evidence of what was agreed, and it verifies outside the platform.
The hardest part of the next program is proving the last one worked. A measurable definition of done in the proposal separates you from whoever is offering a discovery phase. The same record at the close, with the thresholds met and named, is the reference you hand to the next client.
You are approving spend on something that does not exist yet. Acceptance thresholds are dimension, metric and threshold, agreed before the build starts, so you approve a measurement rather than an adjective. Every change is diffed against the baseline you signed and attributed on the day it happened. The record verifies without us, and without whoever built it.
Your input stops getting lost between versions. Open a link, weigh in, and your name travels with the requirement from that day forward.
Approved, testable requirements with fit criteria and permanent IDs, delivered as requirements.json and an acceptance checklist. Feed the approved baseline to your tools, your tests, or your agents. Build against the record, not an interpretation of a deck.
Four positions, one document, and no view about which of them is right.
Isolated project data and role-based access, enforced in the database on every read and write.
An append-only audit log of every version, approval, and inbound submission. Every field and row carries attribution stamped by the server.
Every baseline carries a SHA-256 fingerprint with its recipe printed on the exported document, so anyone holding the record can recompute it. When a client signs, the receipt is signed with Ed25519 and timestamped by two independent authorities. A standalone tool checks all of it offline. A fingerprint on its own proves content. It takes the receipt to prove who signed and when.
1,420 automated checks run on every change, 841 of them against a real Postgres database across 35 suites (as of v3.0.1). Security findings and their fixes are published in the repository, including the ones we caused ourselves.
Export everything, any time. Your record is yours.
Version 3.0.0. Assurance state: self-attested. That means our own gates and suites, published and reproducible, and nothing verified by a third party yet. What that covers, and what it does not.
No third-party penetration test has been commissioned yet, no SOC 2 engagement is signed, and there is no SSO or SCIM. E-signature and cryptographic sealing were on this list and are now live, which is why they are no longer here. We list what is missing for the same reason we publish our own security findings. Once a reader finds one omission, the next question is what else was left out.
One price for the program, whoever is on it. Everyone who authors, reviews, approves, or signs is included. A record that costs more when another reviewer joins is a record that will not get the review it needed.
Larger commitments
The price is fixed. It does not move with the size of the program and it does not move with the number of people who touch the record. The Program record is $85,000 on a $5M program and $85,000 on a $25M one. Whether that is worth it is your judgment and not a claim we make for you.
ReqPub is rolling out through the teams already using it. If someone told you about us, they can bring you in. Email them and ask for the introduction, and they'll connect you with our team directly.
No referral yet? Write us at team@reqpub.com and tell us about the project you're running. We'll take it from there.