Requirements Publications

The accountability record for enterprise AI development.

Projects don't fail at the build. They fail at "that's not what we agreed."

Discovery · Approved baseline · A record that answers with you

What changed

The fee is moving to the outcome.

Clients are writing performance terms into AI contracts, and boards are asking for measured impact instead of pilots. Several of the largest advisory firms now say a meaningful share of their fees is tied to results rather than hours.

An arrangement like that needs one thing before it can exist. The outcome, written down in numbers and agreed by both sides, before the work starts.

Everyone agreed.
Nobody agreed to the same thing.

Requirements live in decks, documents, and email threads. Six weeks in, the scope conversation starts. Reconstructing who approved what, and when, burns senior hours and goodwill. The build team inherits ambiguity. The budget inherits rework.

AI programs raise the stakes. RAND reports that by some estimates more than 80% of AI projects fail, roughly twice the rate of information technology projects that do not involve AI. That figure comes from interviews with 65 practitioners, so read it as most of them rather than as a measured rate. Gartner forecasts worldwide AI spending of $2.59 trillion in 2026. Almost none of it is protected by a document anyone can check.

How it works

Baseline it. Gate it. Export the record.

All parties sign the measurable definition of done.

01Acceptance thresholds
02Requirements with fit criteria
03Named approvals
04One immutable baseline
05One fingerprint verified outside the platform

Baseline

Server-numbered versions with permanent requirement IDs. "What changed since v1.2" is one click, answered requirement by requirement, not from memory.

Gate

A gate is a named decision on a fixed baseline. Name it what your method calls it: Discovery Complete, Design Baseline, Go-Live. The record stores its own readiness at that moment, gaps and warnings named, and nothing reads Approved while a sign-off is pending. One click builds the committee packet: the diff, the sign-offs, the fingerprint.

Export

Every export carries version, status, approvals, and the revision record on the cover. Three artifacts add a SHA-256 fingerprint of the exact baseline with its recipe printed on the page: the client report, the gate packet, and the implementation package. The document arrives with its own receipts.

The platform enforces the structure. Your team supplies the judgment.

ReqPub doesn't write requirements and doesn't replace the people who do. It converts their judgment into a record that holds up.

Works beside your platform

Your program platform reports progress. ReqPub proves agreement.

Trackers govern activity: milestones, status, dashboards. They are good at it, and we build none of it. No Gantt, no RAG rollups, no portfolio dashboards. On purpose.

What a tracker cannot own is what "done" means: requirements with fit criteria, decisions with owners, baselines with named sign-offs. That is the record. It feeds your tracker and your build tools, and there is nothing to migrate.

A gate review on a dashboard is a meeting. A gate on a fingerprinted baseline is evidence.

The same holds beside an AI implementation team, including a vendor's forward-deployed engineers. When the work includes an AI system, the record carries the acceptance table the client signs: dimension, metric, threshold. The build team consumes requirements.json on day one. The client signs the number that stops the meter, before the meter starts.

Client review

Approval from a link. No rollout, no seats, no IT ticket.

The people who approve the work are the busiest people on it. Reviewers open a link, comment in thread, and approve on the record. No accounts, no new software. Their name and timestamp travel with the requirement from that day forward.

Change

Change you can defend.

Scope moves. That's the job. What matters is whether the record moved with it. Every addition, edit, and cut is diffed between baselines and tied to a named approval. The next scope conversation starts from the approved record, not the email archive.

Proof

One baseline. Three artifacts. One fingerprint.

One click on an approved baseline produces the artifacts. The client baseline report: the executive summary, the client-safe brief, the revision record, behind a designed cover. Only what a published brief may contain. Internal fields are absent, not hidden.

The implementation package holds five things. requirements.json, carrying every requirement's permanent ID, statement, fit criterion, priority, and origin. The signed acceptance thresholds, each anchored to a named eval set. The acceptance checklist. The exact diff since the last baseline. The full document.

The SOW exhibit: the acceptance baseline formatted to attach to a statement of work. The acceptance table, the requirements with fit criteria, the recorded sign-offs, blank lines for the exhibit letter and the agreement date, and the verification recipe. Counsel fills in the contract references. The record supplies everything else.

The same SHA-256 sits on all of them. The document the client signed, the exhibit attached to the contract, and the package the builders received are provably the same baseline.

In their words

How people describe it to their own teams

One sentence. ReqPub is where the client signs a measurable definition of done for an AI or technology program, a fingerprinted baseline the engineers build against, so the scope conversation six weeks in starts from the record.

One paragraph. When the builders start fast and the definition of success is still vague, ReqPub fixes the artifact, not the meeting. Requirements get measurable fit criteria and priorities. The client approves by link, with a name and a timestamp on every sign-off. The baseline gets a fingerprint. The engineers get requirements.json and an acceptance checklist on day one. The client gets a report, and the contract gets an exhibit, that carry the same fingerprint. It is not a tracker and it does not replace program tools. It is the evidence of what was agreed, and it verifies outside the platform.

Who it serves

Four positions on every serious program

Leading the work

Win it. Prove it. Get asked back.

The hardest part of the next program is proving the last one worked. A measurable definition of done in the proposal separates you from whoever is offering a discovery phase. The same record at the close, with the thresholds met and named, is the reference you hand to the next client.

Funding the work

Know exactly what you are buying.

You are approving spend on something that does not exist yet. Acceptance thresholds are dimension, metric and threshold, agreed before the build starts, so you approve a measurement rather than an adjective. Every change is diffed against the baseline you signed and attributed on the day it happened. The record verifies without us, and without whoever built it.

Asked to weigh in

Say it once, on the record, from a link.

Your input stops getting lost between versions. Open a link, weigh in, and your name travels with the requirement from that day forward.

Building against it

Build against the baseline.

Approved, testable requirements with fit criteria and permanent IDs, delivered as requirements.json and an acceptance checklist. Feed the approved baseline to your tools, your tests, or your agents. Build against the record, not an interpretation of a deck.

Four positions, one document, and no view about which of them is right.

Security

Built for teams that answer to procurement.

Isolated project data and role-based access, enforced in the database on every read and write.

An append-only audit log of every version, approval, and inbound submission. Every field and row carries attribution stamped by the server.

Every baseline carries a SHA-256 fingerprint with its recipe printed on the exported document, so anyone holding the record can recompute it. When a client signs, the receipt is signed with Ed25519 and timestamped by two independent authorities. A standalone tool checks all of it offline. A fingerprint on its own proves content. It takes the receipt to prove who signed and when.

1,420 automated checks run on every change, 841 of them against a real Postgres database across 35 suites (as of v3.0.1). Security findings and their fixes are published in the repository, including the ones we caused ourselves.

Export everything, any time. Your record is yours.

Version 3.0.0. Assurance state: self-attested. That means our own gates and suites, published and reproducible, and nothing verified by a third party yet. What that covers, and what it does not.

What is not done

No third-party penetration test has been commissioned yet, no SOC 2 engagement is signed, and there is no SSO or SCIM. E-signature and cryptographic sealing were on this list and are now live, which is why they are no longer here. We list what is missing for the same reason we publish our own security findings. Once a reader finds one omission, the next question is what else was left out.

Pricing

Priced per record, not per person.

One price for the program, whoever is on it. Everyone who authors, reviews, approves, or signs is included. A record that costs more when another reviewer joins is a record that will not get the review it needed.

Before the contract
Pursuit record
$7,500
Per pursuit
  • A scope-bearing baseline for the proposal or funding stage
  • Holds no client production data
  • Credits in full toward the engagement tier when the work proceeds
Under $5M
Engagement record
$38,500
Per engagement, 12 months
  • Sealing, the evidence pack, and the close package
  • Every seat and every reviewer included
  • Exports that verify without us
Most programs
$5M to $25M
Program record
$85,000
Per program, 12 months
  • Multiple baselines and multiple gates
  • Webhooks and the agent read surface
  • Everything in the engagement tier

Larger commitments

Above $25M
Enterprise program record
$185,000
Per program, or per portfolio
  • Portfolios running several workstreams against one record
  • Priority incident response
  • A verification session delivered to your security function
Drawn down over time
Programme agreement
$750,000
Ten program records, 24 months
  • Drawn down as you need them
  • One agreement instead of ten
  • Everything in the program tier

The price is fixed. It does not move with the size of the program and it does not move with the number of people who touch the record. The Program record is $85,000 on a $5M program and $85,000 on a $25M one. Whether that is worth it is your judgment and not a claim we make for you.

Every seat included Every reviewer included No per-seat math Fixed price, never a percentage

Available by introduction.

ReqPub is rolling out through the teams already using it. If someone told you about us, they can bring you in. Email them and ask for the introduction, and they'll connect you with our team directly.

No referral yet? Write us at team@reqpub.com and tell us about the project you're running. We'll take it from there.