Business (BUS). BUS is the business of the company: people, organization, legal entities, and the group. A Person is global. Pay, badge, and liability sit on a LegalEntityId. US HoldCo plus subsidiaries. HoldCo is not a plant code. ERP is one company’s books. The group consolidates here — it does not file Form 1120 from a marketing page.
In industry this is Workday / consolidation / badge-system-class capability (capability equals, not products we ship). You are not buying Workday next to a consolidation spreadsheet next to a badge vendor. You are replacing the stack on N23D. 100% Rust we write. One native Rust binary. Not Windows-only.

Skill, clearance, who may complete a work order, and which legal entity owns the books live here. MES does not keep a shadow roster. Cross-entity stock is an intercompany sale, not a warehouse transfer that pretends two companies are one closet. The badge and the paycheck cannot disagree on who someone is. The flowchart is how the business runs — not a bolted-on BPM toy beside the HRIS.
What BUS actually does
BUS merges what used to be sold as separate HR and entity/group products. They share Person and LegalEntityId. They are not two islands.
- Person identity is global. Assignments, employment, pay results, and badge eligibility are per LegalEntityId (employer).
- Org chart is not employer. A dotted line to a HoldCo VP does not move the W-2.
- Legal-entity graph: HoldCo, operating companies, intercompany pairs, books ownership, group close and elimination keys.
- A holding company is a legal person with almost no inventory and a lot of investments. An operating company has inventory, work orders, and people. Same type; different facts. HoldCo is not a plant code in ERP.
- Who may badge into MES, who may approve CCB, who may release PLM — roles on Person, scoped by entity where liability requires it.
- Payroll cash and liability journals post into ERP per employer entity. No fake German wage tax. No fake Lohnsteuer. Honesty about v1 payroll scope is part of the contract.
- Group consolidation sees entity books without stealing them. BUS does not file Form 1120.
- Graphical lifecycles and workflows are first-class in the same binary — States → Transitions → Decisions → Automation — on the same digital thread as CAD, PLM, ERP, and MES.

The flowchart is how the business runs
BUS includes a deeply integrated graphical flowchart / lifecycle engine — Aras Lifecycles & Workflows class, not a side diagram and not a bolted-on BPM toy. The model is executable: States → Transitions → Decisions → Automation. That graph is how hire, terminate, promote, approve pay, open a secondment, and release a group close actually move. Same digital thread as the rest of N23D. One native Rust binary.
- States are real business positions (Draft offer, Active employment, On leave, Terminated, Group books locked) — not labels on a slide.
- Transitions are the only legal moves between states. Each transition has an owner path and an audit stamp. Cancel is a first-class transition on any abandonable lifecycle — role-gated, audited, and allowed to run automations (revoke, notify, compensate, close tasks). Soft-delete outside the graph is not Cancel.
- Decisions branch the graph with named outcomes — not free-text comments pretending to be control. Yes/no is the trivial case. Real decisions are multi-way and data-driven: N outputs from thread fields and lookups (example: COTS | Manufactured in-house | Externally manufactured, plus other factors). Each output is a real continuation path. Missing required input refuses closed with an audit stamp.
- Automation fires from the graph: create thread objects, open tickets/NCRs/changes, post notifications, update eligibility.
- Visual, executable, auditable. If it is not on the flowchart, it is not how the company runs that process.
Cancel and multi-way decisions
Two rules that keep the flowchart honest when real work gets messy.
- Cancel is on the graph. If a process can be abandoned, Cancel (or an equivalent terminal transition) is an explicit edge — not a soft delete, not a hidden admin flag. It is role-gated and audited like every other transition.
- Cancel may run automations. Revoke eligibility, close open tasks, notify stakeholders, reverse provisional posts, open compensating tickets / NCRs / changes. Those automations are data on the Cancel edge and its triggers, not a side script someone remembers.
- Decisions have N outputs from data. A decision is not limited to yes/no. Named outcomes are computed from thread inputs. Classic make-buy example: COTS, Manufactured in-house, or Externally manufactured — each continues a different subgraph (different states, tasks, approvals, automations). Multiple factors may combine; missing required input refuses closed.
- Every decision outcome is a first-class graph edge with permissions, notifications, and automations — the same contract as any other transition.
Triggers on every state
Every state supports triggers. The lifecycle does not wait for someone to remember the next email.
- Before enter — permission checks, required fields, preconditions, refuse with an audit stamp when the Person or role is wrong.
- While in state — in-state / on-timer / on-event: reminders, escalations, eligibility refreshes, thread actions that keep the record honest while it sits.
- After exit — notifications, automations, create/update thread objects, open tickets / NCRs / changes, revoke or grant badge eligibility when the leave is real.
- Triggers may notify roles or named Persons, run automations, and write command breadcrumbs — not anonymous event spam.

Transition permissions and notifications
Who may see, enter, leave, and fire a transition is gated by precise role — and by Person / LegalEntityId where liability requires it. Transition permissions are explicit. “Admin can do everything” is not the default.
- Role-precise gates on every transition. Unauthorized Person is refused with an audit stamp.
- State and transition events notify named roles and Persons (in-app, email, later channels) with an audit trail.
- Notification targets are data on the role and the graph — not a tribal knowledge list in someone’s inbox rules.
- CCB remains the full-spectrum change spine when a cross-domain change is real. The flowchart does not invent a second vault.
What people and employment actually do
- Legal employer and org chart as different trees. BUS owns companies. BUS owns reporting lines. Jobs, positions, FTE, vacancies.
- Workers: employees, contractors, contingent. Hire, change, terminate with reason and rehire eligibility. Transfer between entities is a termination plus hire, or a secondment. Never a silent entity edit. Never an org-chart drag that rewrites the employer.
- Compensation: salary, hourly, allowances. Rates are decimal. No floating-point wages. Benefits eligibility in the US: medical and 401(k) eligibility, not carrier administration.
- Time, attendance, schedules, leave balances. MES may originate a time pair for a work order. BUS owns approval and pay-status. Time on a work order appears on the employing entity’s payroll register and on the work-order cost.
- US multi-state payroll interface, plus a US calculation subset we own (gross-to-net for W-2 employees) or a clean file to an ADP-class provider. Foreign payroll is ingest of pay results from a local provider. We do not compute German Lohnsteuer. Pay result: period, gross, taxes, net, employer cost, produced here for the US or ingested for foreign, always per employing entity.
- I-9, EEO, FLSA classification, workers’ compensation code. Secrets (SSN, bank account) are sealed fields. They are not in the MES badge payload.
- Recruiting lite: requisition on a funded position, applicant, offer letter, handoff to hire. Performance and goals, lite.
- No second badge table in MES. Badge resolves through BUS. Terminate today, badge refused at MES tomorrow.
- A HoldCo finance clerk can be employed by Holdings, Inc. and post on behalf of Manufacturing LLC. Employment entity is not posting entity. On-behalf-of is a BUS posting flag, not a reason to use HoldCo as the vendor.
- Joint-venture employees belong to the JV entity unless a secondment agreement says otherwise. Secondment is an intercompany service plus a BUS assignment flag.
- Hire creates login eligibility. Terminate revokes it. BUS is not the identity provider (IdP); it owns employment eligibility. Entra is the front door.
- Audit: who changed FLSA status, pay rate, entity. Append-only. 100% Rust we write. No Workday or SuccessFactors runtime.

Org chart and precise roles
The org chart is first-class: reporting lines, LegalEntityId-aware where employment lives. A dotted line to a HoldCo VP still does not move the W-2. Roles are not vague job titles alone — they carry permissions, transition rights, notification targets, and EA ownership.
- Org chart and employer tree stay separate. Dragging boxes does not rewrite LegalEntityId.
- Role definitions are specific: who may fire which transition, who is notified, who owns which EA capability or app node.
- Those roles drive live permissions and live notifications — the chart is not decoration for an all-hands slide.
- CCB approvers, MES badge eligibility, and PLM release rights resolve through BUS Persons and roles.
Career pathing on the same thread
Roles form directed paths: role → next role (lattices allowed — multiple next roles). Career edges are workforce-planning data on the thread. Person history can reference path progress. This is not a second HR silo outside BUS.
- Useful for eligibility, training gates, and “who can approve this transition after promotion.”
- A Person’s current role and allowed next roles are queryable — not trapped in a separate LMS or HRIS island.
- Promotion that changes transition rights updates the same role model the flowchart already uses.
- No parallel career product bolted beside BUS. One Person record. One role graph.

Enterprise Architecture on the same graphical interface
Enterprise Architecture — capabilities, applications, interfaces, roadmaps — is authored on a similar graphical / model interface (LeanIX class). The model defines the business. It is not a slide deck beside the system. Cross-domain EA changes still go through CCB. Identity remains Entra as IdP front door; BUS owns eligibility.
- EA nodes link to AssetId / apps where TIX owns operational life; ERP still sees only the financial view.
- Same class of graphical UI as lifecycles — one mental model for “how we run” and “what we run on.”
- Capability and app ownership hang off precise roles, not anonymous swimlanes.
- We do not invent a second change board for architecture. CCB is the spine.
What legal entities and the group actually do
- Legal-entity graph: corporation, LLC, branch, disregarded entity, foreign, joint venture. Roles: holdco, opco, sales, IP, captive, dormant, JV. Ownership edges with percent, share class, effective dates, control basis (voting, VIE, contract).
- Multiple books per entity: statutory US GAAP, IFRS, local statutory, federal tax, state tax, management. Each with currency and chart of accounts. One operational event can post into several books. Statutory, tax, and management may differ. That is a book difference, not an error.
- Three consolidation trees on the same entities: group GAAP, tax group, management view. Legal is not tax is not management.
- US 1502 membership tests: only includible US corporations owned 80% or more. An LLC disregarded entity is not a 1502 member. Its owner is. A foreign corporation is out. Partnerships and LLCs taxed as partnerships are out. Adding a foreign corp to a 1502 group is a hard fail except for documented exceptions.
- ASC 810 control (voting or VIE) consolidates 100% of the subsidiary, then a noncontrolling-interest line. Foreign sub: local books, translation to USD, cumulative translation adjustment. Not in the US consolidated tax return.
- A branch is not a legal person. Books may still exist for statutory or management. A disregarded entity is one legal person, disregarded for federal tax, still real for state and contract. Tax attributes roll to the owner. Legal books stay on the LLC if the LLC is the contracting party.
- Site and plant hang off an entity. They never replace one. A user works in an entity context. Cross-entity postings are intercompany, not a site transfer with extra fields.
- Item, material variant, and party are group identities. Commercial views (cost, tax code, planning policy, preferred vendor) are per entity. A part designed once can be bought by the GmbH and made by the Nevada LLC. Two commercial rows. One item id.
- Group close: lock entity books, translate foreign functional to group presentation (USD), run the elimination set, post noncontrolling interest, produce group statements. Posted group eliminations live in a consolidation book. BUS journals are not silently deleted.
- Intercompany is always a pair. Creating seller AR creates buyer AP in the same transaction, or the post fails. There is no one-sided intercompany invoice. Agreements carry transfer-pricing method (CUP, resale, cost-plus, residual, profit-split) and index (markup, rate, royalty). Document kinds: invoice, loan, royalty, management fee, stock transfer. An elimination key so consolidation can match.
- Inventory moving from a Nevada plant to a German plant is an intercompany sale, or consignment with an explicit contract. It is not an ERP transfer order. Site transfer is same-entity only. Same-entity warehouse move is a transfer. Cross-entity move is an intercompany sale or explicit consignment. No third kind.
- Unrealized profit in inventory: Nevada sold to the GmbH at markup, GmbH still holds the lot, group inventory comes back to Nevada cost. That rule reads the MES/ERP lot, the intercompany invoice, and Materials cost.
- Elimination catalog, configured, not coded per deal: AR versus AP, revenue versus COGS or expense, unrealized profit in inventory, investment in sub versus sub equity, intercompany loans versus notes.
- Intercompany loans: principal, interest, withholding on cross-border, long-term investment CTA election as a flag, not a comment. US 1502 members: intercompany gain timing follows matching and acceleration. The tax book may defer what GAAP already recognized.
- Shared-services on-behalf-of: HoldCo employees do AP for US operating companies on behalf of those entities. The invoice still posts in the OpCo book. On-behalf-of is a posting flag, not a reason to use HoldCo as the vendor.
- Tax group membership is stored here. BUS does not compute Form 1120 or Form 1122. Build the graph so tax has somewhere to hang.
- FX rates, translation, CTA. Group chart of accounts plus maps. Every posting in the rest of the stack carries LegalEntityId. Peers that post without it do not compile.
- The structure this model must represent without schema changes: US C-corp HoldCo, Nevada manufacturing LLC (disregarded), US sales C-corp, IP LLC, Europe GmbH, Mexico S. de R.L., a 60% JV with noncontrolling interest.
- 100% Rust we write. Industry-class group reporting is the bar. We do not ship Oracle FCCS or SAP Group Reporting.

Identity, devices, and action stamps
BUS owns employment eligibility and the Person record. It does not pretend to be the company’s identity provider. Sign-in uses what IT already runs — primarily Microsoft Entra ID (Azure), with room to federate Okta or AD through the same door. N23D checks the badge. It does not issue the badge. WordPress is the marketing site. It is not identity.
Stupid-simple altitude: executives hear N23D = more money because every action is attributable. Technical hears familiar infrastructure = no work — Azure sign-in, company VPN, enrolled machines. Drill-down below is for the people who pull.
Access is layered on purpose:
- VPN / company pipe — off the network, off the vault. No pipe, no sync into company peers.
- Device (ITAM in TIX) — every laptop is an AssetId. At install, N23D places a device key in the TPM (or uses Entra device join). The vault trusts enrolled AssetIds. This is not a MAC spreadsheet. MACs spoof and vanish inside tunnels.
- Person badge — Entra login: password, Windows Hello, or a security key. Fingerprint only when Hello already provides it. No sci-fi gate. Hire creates eligibility in BUS. Terminate revokes it.
The data plane does not require cloud. Laptop, site vault, and cold vault replicate unique encrypted blocks peer to peer. Triple durability is a product default the customer never configures. Azure is the familiar front door and an optional peer shape — not the landlord of the CAD.
Every action hangs off the Person. Device, time, site/vault topology (not GPS), command, object (Item/VariantId), app build hash, and a short command breadcrumb are stamps on that user’s action — not an anonymous event stream. Ask “what did Maria do?” and the thread answers. When she quits, revoke Maria; new stamps stop.
- We do not become the customer’s IdP.
- We do not key device trust off MAC addresses.
- We do not log raw clicks like spyware; we keep a command breadcrumb that explains how an approval was reached.
- We do not put the digital thread’s source of truth only inside a public-cloud subscription.
How N23D puts this in one place
Most stacks fail the day after save, when the model, the ticket, or the invoice becomes someone else’s import. N23D removes that day. This module reads the same record as the others.
- one native Rust binary: N23D. 100% Rust we write. No vendor kernel, ledger, PLC runtime, HRIS, or ITSM as the source of truth. File readers and protocol bridges are interchange. Not Windows-only.
- One identity plane: Item, VariantId, Person, and AssetId are global. Invoice, work order, inventory, quote, pay result, and NCR sit on a LegalEntityId.
- One digital thread: modules read the same record. There is no daily STEP shuffle as the workflow. Check-in is PLM save. CAM does not fork the body.
- Command::Core is the identity and policy plane. CCB is the full-spectrum change spine (not a second vault). TIX holds operational life of assets; ERP sees only the financial view.
- BUS flowchart / lifecycle engine, org roles, career paths, and EA model live in the same binary — not a BPM sidecar and not a LeanIX export.

- Materials only from MAT. CAD selects VariantId. Missing density means mass is unknown — we do not invent a number so a BOM or plot closes.
- ERP is one company’s books. BUS holds HR, org, legal entities, group consolidation, lifecycles, roles, career pathing, and EA model. HoldCo is not a plant. No fake Form 1120. No fake Lohnsteuer.
- Item, VariantId, Person, and AssetId stay global. Invoice, WO, inventory, quote, pay, and NCR sit on LegalEntityId.
- MES badge resolves through BUS. PMO resources are BUS persons. CCB approvers are BUS persons.
- ERP never consolidates the group. TIX never owns Person. PLM never owns the W-2.
What we will not fake
This is the product promise, not a claim that every solver and every pack already ships in the binary today. Industry-class names below are capability equals. They are not products we ship.
- We do not ship Workday or a consolidation pack as the runtime.
- We do not file 1120 from BUS. We do not treat HoldCo as a plant.
- We do not fake Lohnsteuer or other jurisdiction wage-tax theater in v1.
- We do not ship a bolted-on BPM toy or a slide-deck EA product beside the thread. Flowchart engine + org/roles/career + EA model are in scope for BUS depth; tax engines are not.
- File readers are interchange.
If the badge, the books, and the group still live in three islands, we failed. If the org chart cannot gate a transition and the career path lives in another silo, we failed. One business record.
Natively connected, not glued together
N23D runs one data model across design, make, operate, and the business. Nothing is exported as the daily path. Nothing is re-keyed. Nothing is lost in translation between vendors.
- One data model. A part, an order, a nonconformance, a ticket, and a change point at the same objects. No mapping tables, no nightly sync, no drift.
- No export/import loss. Geometry, tolerances, revisions, asset state, and history stay intact because they never leave the system as the daily path.
- Auditability by default. Every change is versioned and attributable, so traceability is a query, not a project.
- Speed. 100% Rust: native performance, small footprint, no runtime surprises.
- Sovereignty. Your data, your infrastructure, your rules. No lock-in.
