Cardona Pipeline ToolsBIM Bid Engine Open prototype

Rolling product whitepaper - July 26, 2026

A review-first bid engine for traceable electrical package pricing.

BIM Bid Engine turns normalized electrical schedule data into explainable supplier candidates, estimator-approved RFQ packages, reconciled quotes, and controlled proposal pricing. Every derived result preserves its evidence, and every material decision remains human-controlled.

01

Explain before automating

Matches expose their score, missing attributes, and hard conflicts before an estimator acts.

02

Provenance by default

Source file, row, page, catalog version, reviewer, and reason follow every derived artifact.

03

Human approval is a gate

No candidate becomes an RFQ line and no unresolved quote variance becomes proposal pricing automatically.

System model

One evidence chain, nine delivery stages.

The prototype uses dependency-free Python domain modules and a static HTML interface. Each stage narrows ambiguity while retaining the original source.

InputBIM scheduleCSV, document pages
to
NormalizeTyped itemsSource-row provenance
to
MatchCandidatesEvidence and conflicts
to
ReviewDecisionsActor, reason, audit
to
CommercialRFQ and quoteVariance-controlled pricing

Deterministic core

Electrical compatibility stays authoritative.

  • Category, voltage, wattage, and mounting are hard gates.
  • Image similarity retrieves candidates but never overrides conflicts.
  • Scores are repeatable and visible to the estimator.

Review boundary

Automation proposes; estimators decide.

  • Approval, rejection, exclusions, notes, and quantity changes are audited.
  • Supplier substitutions are re-checked for electrical compatibility before review.
  • Readiness fails while required decisions remain unresolved.

Integration boundary

Supplier access begins with permission.

  • Only approved API, export, punchout, or explicit-permission channels qualify.
  • Catalog versions and content digests create immutable snapshots.
  • Credentials, scraping, and live access remain outside the public prototype.

Rolling build log

From contract-first foundation to operational gates.

Each sprint adds one reviewable capability layer. Status reflects the current local prototype, not a deployed production service.

  1. 0

    Foundation

    Product boundaries and synthetic evidence

    Defined data contracts, fixture validation, repository safeguards, and the first interactive preview.

    • Synthetic-only committed fixtures
    • Dependency-free validation
    • No active supplier integration
    Complete
  2. 1

    BIM schedule intake

    Normalize Revit-exported schedule data

    Added CSV intake, header detection, quantity aggregation, field validation, and source-row provenance.

    Complete
  3. 2

    Supplier catalog intake

    Create a trusted searchable product pool

    Added catalog import, normalization, duplicate detection, conservative voltage compatibility, and filters.

    Complete
  4. 3

    Deterministic matching

    Rank candidates and expose every conflict

    Implemented transparent weighted scoring with hard electrical gates and repeatable candidate ordering.

    Complete
  5. 4

    Estimator review

    Turn eligible candidates into human decisions

    Added unresolved queues, approval and rejection reasons, notes, exclusions, quantity provenance, and audit history.

    Complete
  6. 5

    RFQ package

    Assemble traceable supplier request lines

    Added approved-review requirements, SKU consistency, conflict rejection, BIM provenance, and deterministic JSON.

    Complete
  7. 6

    Quote and proposal

    Reconcile supplier responses before pricing

    Added substitution and quantity-variance review, controlled markup, proposal gates, and a dedicated HTML workspace.

    Complete
  8. 7

    Document intelligence

    Preserve evidence from PDF, OCR, and images

    Added page-level extraction contracts, OCR review gates, source-image provenance, and visual-suggestion safety boundaries.

    Complete
  9. 8

    Supplier integration

    Define permission-based catalog access

    Added approved-channel authorization and SHA-256 verified catalog snapshots without credentials or network execution.

    Complete
  10. 9

    Operational readiness

    Make safety boundaries testable release gates

    Gates internal review on tests, provenance, synthetic-data policy, human decisions, credential findings, and integration state.

    • End-to-end synthetic workflow validated
    • Repeatable repository audit passing
    • Deployment remains disabled
    Complete
  11. 10

    Private pilot foundation

    Define access, isolation, retention, and durable audit boundaries

    Adds synthetic role and project contracts, tenant-aware access, exact retention periods, and checkpointed hash-chained audit records.

    Complete
  12. 11

    Authentication and data lifecycle

    Fail closed across sessions, deletion, backup, and recovery

    Adds tenant-bound session decisions, MFA and revocation gates, administrator-separated deletion, legal holds, verified backup bytes, and audit-head recovery checks.

    Complete
  13. 12

    Administration and assurance

    Make private-pilot controls visible and reviewable

    Added session revocation, legal-hold release, supplier permission expiry, recovery-drill evidence, and a responsive synthetic administration dashboard.

    Complete
  14. 13

    Pilot workflow integration

    Fail closed across sessions, tenants, projects, and roles

    Integrated authentication and authorization evidence into role-specific workflow decisions with reconstruction hardening.

    Complete
  15. 14

    Pilot operations and observability

    Make operations diagnosable without external telemetry

    Added correlated events, scoped health evidence, deterministic alerts, escalation timing, redacted diagnostics, and a synthetic operator dashboard.

    Complete
  16. 15

    Pilot configuration and change control

    Make configuration versioned, attributable, and reversible

    Adds scoped snapshots, computed digests, hardened drift evidence, separate approvals, ordered effective dates, fail-closed activation, rollback evidence, and a synthetic configuration dashboard.

    • Unknown settings fail closed as security-sensitive
    • Rollback creates a new version from a chronologically historical target
    • Infrastructure mutation, secrets, and deployment automation remain prohibited
    Complete
  17. 16

    Evidence reconstruction assurance

    Keep security evidence self-verifying after reconstruction

    Adds rollback chronology context, hostile reconstruction regression coverage, and one explicit fail-closed configuration risk policy.

    • 148 automated tests passing
    • All configuration evidence rejects non-synthetic reconstruction
    • Persistence, providers, supplier access, and deployment remain disabled
    Complete
  18. 17

    Pilot experience and accessibility

    Make the review workspace easier to operate and audit

    Adds keyboard-friendly review queues, live status announcements, focus restoration after row rebuilds, DOM-safe rendering, and regression tests for the main pilot review surface.

    • 153 automated tests passing
    • Review queue tabs expose selected state and roving focus
    • Human approval and synthetic-only boundaries remain intact
    Complete
  19. 18

    Internal release candidate

    Freeze acceptance evidence without expanding authority

    Adds a synthetic RC manifest for tests, fixtures, repository audit, end-to-end acceptance, threat model, recovery, accessibility, and documentation.

    • 159 automated tests passing
    • Deployment, live supplier access, and real data remain disallowed
    • Missing, duplicate, failed, or non-synthetic gates are rejected
    Complete
  20. 19

    Post-RC reconstruction hardening

    Close the release-gate reconstruction gap

    Hardens RC evidence against subclass and reconstructed-object bypasses, exports the safe factory, and makes repository audit exercise the RC contract.

    • 164 automated tests passing
    • Audit output now includes inert RC authority evidence
    • Deployment, live supplier access, and real data remain disallowed
    Complete
  21. 20

    Audit evidence execution

    Make RC evidence command-backed on demand

    Adds an opt-in audit mode that runs validation commands, records command evidence, and blocks internal review when executed evidence fails.

    • 172 automated tests passing
    • Command-backed and named-evidence gate sets are pinned
    • Deployment, live supplier access, and real data remain disallowed
    Complete
  22. 21

    Private-pilot plan

    Make pilot prerequisites exact before activation

    Adds a synthetic governance plan for repository privacy, history audit, identity, storage, secrets, backup, supplier access, deployment approval, real-data governance, and human approval policy.

    • 187 automated tests passing
    • Plan verification rejects unresolved and live-looking evidence
    • Providers, storage, deployment, suppliers, and real data remain disabled
    Complete
  23. 22

    Governance approval matrix

    Track human decisions without creating a launch switch

    Adds a synthetic matrix for pending, blocked, and approved private-pilot prerequisites, tied to a verified plan digest and exact gate order.

    • 201 automated tests passing
    • Matrix binding and digest verification reject tampering
    • Deployment, providers, storage, suppliers, and real data remain disabled
    Complete
  24. 23

    Demo polish

    Make the prototype easier to explain live

    Adds a three-minute walkthrough, visible demo guardrails, and direct links from the main workspace to the whitepaper and approval matrix.

    • 203 automated tests passing
    • Main bid page has whitepaper and governance links
    • No deployment, providers, storage, suppliers, or real data are activated
    Complete
  25. 24

    Demo script and review narrative

    Make the walkthrough repeatable

    Adds a five-minute demo, 15-minute deep dive, stakeholder Q&A, and presenter guardrails that avoid production-readiness overclaims.

    • 205 automated tests passing
    • README, whitepaper, and review bundle point to the demo script
    • Deployment, suppliers, proposal submission, and real data remain outside scope
    Complete
  26. 25

    Demo QA

    Dry-run the walkthrough before sharing

    Adds presenter setup notes, talk-track QA, local URL checks, and link-target tests for the demo path.

    • 207 automated tests passing
    • Walkthrough targets are verified at source level
    • Deployment, suppliers, proposal submission, and real data remain outside scope
    Complete
  27. 26

    Governance review prep

    Make private-pilot gate decisions explicit

    Adds owner, approval question, required evidence, blocker, current status, and non-authorizing boundary for every private-pilot gate.

    • 209 automated tests passing
    • All ten governance gates are pinned in review docs
    • No gates are approved and no activation authority is created
    Complete
  28. 27

    Governance decision capture

    Record outcomes without creating launch authority

    Adds a decision log where each private-pilot gate starts pending and activation authority remains none.

    • 211 automated tests passing
    • Each canonical gate appears exactly once
    • No gates are approved and no activation authority is created
    Complete
  29. 28

    Governance evidence intake

    Define safe evidence placeholders before collection

    Adds a not-collected evidence intake row for every private-pilot gate, with public-repo evidence prohibitions and activation authority set to none.

    • 213 automated tests passing
    • Each canonical gate has one not-collected intake row
    • No sensitive evidence is collected or committed
    Complete
  30. 29

    Design system spec

    Make future UI work agent-readable

    Adds a root design contract covering tokens, layout, components, interactions, accessibility, and non-authorizing language.

    • 215 automated tests passing
    • Design rules match current static UI tokens
    • No runtime behavior or authority changes
    Complete
  31. 30

    UI conformance audit

    Check the shareable demo path against the design system

    Adds a source-level audit for tokens, shell conventions, safety language, review boundaries, and residual UI hardening work.

    • 218 automated tests passing
    • README, whitepaper, and review bundle link the audit
    • No runtime behavior or authority changes
    Complete
  32. 31

    Quote DOM hardening

    Make quote rendering safer before future real-data paths

    Replaces quote workspace dynamic HTML rendering with DOM creation and text assignment while preserving variance review gates.

    • 219 automated tests passing
    • site/quote.js contains no dynamic innerHTML
    • No runtime authority changes
    Complete
  33. 32

    Secondary DOM hardening

    Make remaining preview scripts DOM-safe

    Replaces intake, catalog, and matching dynamic HTML rendering with DOM creation and text assignment.

    • 220 automated tests passing
    • Runtime scripts under site contain no dynamic innerHTML
    • No runtime authority changes
    Complete
  34. 33

    Browser QA evidence

    Pin the local browser walkthrough path

    Adds a local-only browser QA evidence artifact for the shareable static workflow after DOM hardening.

    • 222 automated tests passing
    • Required local routes are pinned
    • No deployment, hosting, screenshots, or real data
    In progress

Trust and control

What the prototype intentionally does not do.

01

No automatic purchasing

The system prepares evidence and package-pricing requests. It does not place orders or submit bids.

02

No silent substitutions

Changed SKUs and quantities are visible, blocked from pricing, and require a documented human decision.

03

No unapproved data access

Supplier scraping, credentials in source, proprietary catalogs, and live integrations are prohibited.

04

No visual override

OCR and image similarity can add evidence, but they cannot defeat incompatible electrical attributes.

Current checkpoint

Local browser QA evidence for the shareable workflow.

The QA artifact pins the local route path for review, quote, intake, catalog, matching, whitepaper, and documentation checks while keeping deployment, providers, storage, suppliers, screenshots, and real data outside the authorized boundary.

Open browser QA evidence