Capability Matrix · Component 4 — Pipelines and Ingest
Pipelines, scored. The technical winner isn't always the procurement-defensible default.
Tenzir, Vector, Cribl, Kafka Connect, and at Archetype C, AWS Kinesis Firehose + Lambda as a fifth candidate. Nine criteria per archetype, weights summing to 100, scores 1–5 with evidence tiers per cell, weighted totals with honest bounds. The headline finding isn't in any single number: it's the gap between the technical winner and the procurement-defensible default at Archetype A, and the way that gap collapses at Archetype C into a three-way photo finish.
v1-draft · 2026-05-25 · revalidate by 2026-11-25 · 117 score cells total (4 candidates × 9 criteria × 3 archetypes = 108, plus 9 for Firehose+Lambda at C), drawn from the version-controlled C4 pipelines scoring YAML that backs every cell on this page, whose weighted totals a linter re-derives from the score-times-weight cells so no total here can drift from its components. The v1-draft label is that scoring file's own status: no Pipelines re-scoring cut has shipped since 2026-05-25, so this page does not claim the v1.2/v1.3 stamps its sibling matrices earned in later evidence passes.
Archetype A — cost-reduction-led
500 GB/day. 80% of value in 20% of events. Schema-on-read SIEM downstream. 1–2 engineers.
Default reduction ratio carries 25 of 100 weight points; aggressive reduction adds another 10. Together they're more than a third of the score. OCSF fidelity sits at weight 5 here; the schema work happens downstream at query time.
Winner at a glance
Tenzir 3.75–3.95 leads on technical merit. Cribl 3.35–3.55 is the procurement-defensible default. Vector 3.25–3.45 is the OSS fallback when license cost is the binding constraint. Kafka Connect 2.00–2.20 is wrong-tool-for-archetype, not wrong-tool-overall.
The scoring table — Archetype A
Cells show score (1–5) with a six-word evidence flag. Red is 1; green is 5. Color dominates because this is the matrix product; it should read as a scored matrix at a glance, not as a styled spreadsheet.
| Criterion | Weight | Tenzir | Cribl | Vector | Kafka Connect |
|---|---|---|---|---|---|
default_reduction_ratio Out-of-box SIEM-volume reduction | 25 | 3 Tier C · pipe-design dependent | 4 Tier B · tuned not default | 3 Tier B · VRL-author dependent | 1 Tier B · transport not filter |
aggressive_reduction_ratio Ceiling with intentional tuning | 10 | 4 Tier C · ML-rule capable | 4 Tier B · EDR 90% net flows 98% | 3 Tier B · no security templates | 1 Tier B · no sampling primitive |
ocsf_normalization_fidelity Schema-on-write OCSF coverage | 5 | 4 Tier B · OCSF-native design | 3 Tier B · via paid Packs | 2 Tier B · no first-class OCSF | 2 Tier B · downstream Spark/dbt |
cross_source_schema_correlation Pipeline-layer enrichment / join | 5 | 3 Tier C · OCSF semantic layer | 3 Tier B · 100+ integrations | 2 Tier C · observability-generalist | 2 Tier C · join in engine layer |
lines_of_config_soc_ruleset Pipeline expressiveness for detection-as-code | 15 | 4 Tier B · TQL declarative Git-ops | 4 Tier B · GUI + JS 50-200 LOC | 3 Tier B · VRL less opinionated | 2 Tier B · JSON connector verbose |
resource_consumption_cpu_memory CPU/RAM per GB ingested | 15 | 4 Tier C · C++ 800K events/sec | 4 Tier B · stateless linear scale | 4 Tier C · vendor 200K rec/sec | 2 Tier B · JVM broker overhead |
pricing_model TCO across OSS, consumption, SaaS | 10 | 5 Tier B · open-core $90-150K | 2 Tier B · $0.10-0.30 per GB | 5 Tier A · MPL-2.0 free OSS | 4 Tier A · Apache 2.0 free |
vendor_lockin_portability Pipeline-language portability / exit cost | 10 | 5 Tier B · Apache 2.0 forkable | 2 Tier C · proprietary pipe DSL | 4 Tier A · standard sinks portable | 4 Tier A · standard Kafka protocol |
in_house_skill_base Held null at standing matrix | 5 | null | null | null | null |
| Weighted total | 3.75–3.95 | 3.35–3.55 | 3.25–3.45 | 2.00–2.20 | |
| Evidence completeness | 0.889 | 0.889 | 0.889 | 0.889 |
Decision shape: the technical winner vs. the procurement-defensible default
Tenzir leads by roughly 0.40 over Cribl on weighted total, and the lead is real on every criterion that the matrix scores directly: OCSF-native by design, Apache 2.0 core, TQL expressiveness, pipe-layer detection at 15–50ms vs. query-based detection at 5–30s. But the weighted total isn't the engagement recommendation by default. Tenzir's production-evidence base sits at Tier B/C on most criteria; public customer count is under 100 known deployments, and no published Fortune-500 OCSF lossiness audit at 5+ TB/day exists. Cribl arrives at the same engagement carrying 50+ Fortune-100 production references (vendor-reported and anonymized, so Tier B at best under MDR-0003), RiverSafe's partner-published 40%-reduction measurement (Tier C — RiverSafe is a Cribl partner), and strong practice anchors on most criteria. The framing I use with clients: "the matrix says Tenzir; the procurement committee says Cribl; both are right." Tenzir is the upgrade path when four conditions hold simultaneously: OCSF is the canonical schema and is non-negotiable, open-source exit strategy is a procurement requirement, the team can sustain 0.5–1 FTE of TQL rule authoring, and the engagement has appetite for a 6-week paid PoC at the customer's actual volume. Otherwise I recommend Cribl and document the evidence-asymmetry reasoning explicitly so the customer's CISO and procurement office see the same artifact.
Where the ranking is fragile
Three places the A ranking moves on plausible evidence updates. First, Tenzir's default_reduction_ratio sits at score 3 on Tier C evidence per A-03-tenzir-ocsf-unaudited-at-scale; if the H1-COST-02 head-to-head benchmark anchors 70–90% as a true default, the score lifts to 4–5 and the weighted total climbs to ~4.00–4.20 at score 4, past ~4.25 at score 5. Independent measurement showing 30–50% default drops the score to 2 and the weighted total falls to ~3.50, contesting Cribl outright. Second, Cribl's own default_reduction_ratio sits at 4 on the same shaky vendor-claim foundation per A-02-cribl-70-90-is-tuned-not-default; the 70–90% headline is the aggressive-tuned ceiling, not the out-of-box default. If the benchmark anchors the low end at 30%, Cribl moves to 3 and the gap to Vector closes meaningfully. Third, Tenzir's ocsf_normalization_fidelity is scored 4 at Tier B, but because OCSF fidelity carries only weight 5 at A, an independent audit showing > 10% lossiness on three or more source classes drops the score to 3 and the weighted total only to ~3.70–3.90 (a 0.05 move: one score point × weight 5 ÷ 100), so the A ranking barely feels it. The same downgrade bites at Archetype B, where the criterion carries weight 30 and takes the total to ~3.40–3.60 — see the B fragility note below.
Disclosure block. No active partnership disclosures among the four Archetype A candidates.
Archetype B — schema-normalization-led
200 GB/day from 10+ sources. OCSF-conformant events to Iceberg. 2–3 engineers writing custom pipes.
OCSF normalization fidelity jumps from weight 5 (at A) to weight 30, the largest weight shift in the full matrix. Cross-source correlation triples from 5 to 15. Reduction-ratio weights drop. The archetype is asking a different question.
Winner at a glance
Tenzir 3.70–3.90 opens its lead to ~0.50 over Cribl. Cribl 3.20–3.40 remains the procurement-defensible default. Vector 2.70–2.90 falls further behind, exposing the observability-generalist as a structural OCSF misfit. Kafka Connect 2.00–2.20, same misfit as A.
The scoring table — Archetype B
Same nine criteria, re-weighted. OCSF fidelity at 30, cross-source correlation at 15, lines-of-config at 15; that's 60% of the score on OCSF + correlation + expression.
| Criterion | Weight | Tenzir | Cribl | Vector | Kafka Connect |
|---|---|---|---|---|---|
ocsf_normalization_fidelity Largest weight shift in matrix | 30 | 4 Tier B · OCSF-native design | 3 Tier B · via vendor Packs | 2 Tier B · per-source custom VRL | 2 Tier B · downstream Spark/dbt |
cross_source_schema_correlation Weight triples from 5 to 15 | 15 | 3 Tier C · OCSF semantic layer | 3 Tier B · 100+ integrations | 2 Tier C · correlation downstream | 2 Tier C · SQL-engine layer |
lines_of_config_soc_ruleset Same weight as A | 15 | 4 Tier B · TQL Apache 2.0 | 4 Tier B · GUI plus JS-like | 3 Tier B · VRL 10 source maps | 2 Tier B · verbose JSON SMTs |
default_reduction_ratio Drops from 25 to 10 | 10 | 3 Tier C · pipe-design dependent | 4 Tier B · tuned not default | 3 Tier B · VRL-author dependent | 1 Tier B · transport not filter |
resource_consumption_cpu_memory Drops from 15 to 10 | 10 | 4 Tier C · C++ 2-3 nodes | 4 Tier B · stateless linear scale | 4 Tier C · vendor 200K rec/sec | 2 Tier B · JVM broker overhead |
aggressive_reduction_ratio Drops from 10 to 5 | 5 | 4 Tier C · ML rule capable | 4 Tier B · EDR 90 flows 98 | 3 Tier B · routing not reduction | 1 Tier B · no sampling primitive |
pricing_model Drops from 10 to 5 | 5 | 5 Tier B · open-core $90-150K | 2 Tier B · $0.10-0.30 per GB | 5 Tier A · MPL-2.0 free OSS | 4 Tier A · Apache 2.0 free |
vendor_lockin_portability Drops from 10 to 5 | 5 | 5 Tier B · Apache 2.0 forkable | 2 Tier C · proprietary pipe DSL | 4 Tier A · standard sinks portable | 4 Tier A · standard Kafka protocol |
in_house_skill_base Held null at standing matrix | 5 | null | null | null | null |
| Weighted total | 3.70–3.90 | 3.20–3.40 | 2.70–2.90 | 2.00–2.20 | |
| Evidence completeness | 0.889 | 0.889 | 0.889 | 0.889 |
Decision shape: what changes when OCSF carries 30 of 100
Tenzir's weighted total (3.70–3.90) is roughly equal to Archetype A's (3.75–3.95). What changes is its position in the ranking, not its absolute score. The +130 weighted points gained from OCSF + correlation under B are offset by ~135 lost on the two reduction ratios, pricing, lock-in, and resource. The weights moved between dimensions and Tenzir scored high on both ends, so net is roughly zero. Cribl drops harder because Pack-mediated OCSF normalization is scored 3 vs. Tenzir's 4 at the 30-weight criterion; that's a 30-point gap on a single criterion. Vector falls further still: its score-2 on OCSF at weight 30 is a 60-point gap to Tenzir, exposing the observability-generalist design as structural OCSF misfit for this archetype. The honest decision shape: run a source-coverage audit before committing. Does Cribl's Pack inventory map every one of your 10+ sources (CloudTrail, Zeek, EDR, identity, SaaS APIs) to OCSF with zero gaps? If yes, Cribl + route-by-fidelity is the procurement-defensible default. If gaps exist, Tenzir's OCSF-native path is materially stronger, and the gap-count drives the engagement scoping.
Where the ranking is fragile
The B ranking pivots on a Tier-A datapoint that doesn't exist yet: an independent OCSF lossiness audit for Tenzir at production scale (5+ TB/day). One pending caveat carried on the score itself: the 4 predates the first-party 2026-06-14 pipeline-normalization-fidelity measurement, which found Tenzir's shipped Zeek→OCSF mapping class-right (100% Network Activity) but activity-wrong (activity_id correct on 17%) with no shipped CloudTrail/Sysmon/auth mapping in the shape those sources actually emit, so the availability-vs-fidelity re-score is an open owner scoring decision. Per A-03-tenzir-ocsf-unaudited-at-scale, Tenzir's architecture is sound but unaudited at 5+ TB/day. If an audit shows > 10% lossiness on Zeek or CloudTrail or EDR mapping, the OCSF score drops from 4 to 3, the weighted total falls to ~3.40, and Cribl pulls roughly even on the procurement-defensible axis it already owns. Conversely, a clean lossiness audit at < 5% lifts Tenzir's score to 5 at weight 30 and the total climbs to ~4.00. At that point Cribl's Pack approach becomes hard to defend on technical grounds and the engagement reasoning shifts toward "use Cribl only when the Pack inventory exactly fits and the customer values GUI workflows."
Disclosure block. No active partnership disclosures among the four Archetype B candidates.
Archetype C — AWS-native ingest
AWS-committed. Iceberg+Glue settled. Pipeline scored against the Firehose+Lambda baseline.
Firehose+Lambda was implicit at v1.0; v1.2 promotes it to an explicit fifth candidate. Pricing defensibility at weight 20, lock-in at weight 15, OCSF fidelity at weight 20. The AWS economics are the reference and any vendor licensing layers on top. The in_house_skill_base criterion drops to weight 0 (AWS skill is the standing assumption).
Winner at a glance
Vector 3.55, Tenzir 3.40, Firehose+Lambda 3.35: a 0.20 spread across three genuinely-different procurement postures. No dominant winner. Cribl 2.95 drops to #4. Kafka Connect 2.75 stays misfit. The decision pivots on lock-in posture, not weighted total.
The scoring table — Archetype C
Five candidates, nine criteria. in_house_skill_base at weight 0; null × 0 = 0 deterministically, no bounds spread.
| Criterion | Weight | Vector | Tenzir | Firehose+λ | Cribl | Kafka Connect |
|---|---|---|---|---|---|---|
ocsf_fidelity Drops from B's 30 to 20 | 20 | 2 Tier B · VRL observability-generalist | 4 Tier B · TQL OCSF design-center | 3 Tier B · Lambda plus Glue ETL | 3 Tier C · via vendor Packs (unmeasured) | 2 Tier B · KSQL or Streams on top |
pricing_model_defensibility AWS pay-per-use is the reference | 20 | 5 Tier A · MPL-2.0 no licensing | 3 Tier B · commercial features add | 5 Tier A · published pay-per-use pricing | 2 Tier B · own essay: per-volume licensing | 4 Tier B · MSK Serverless option |
vendor_lockin_score The C decision pivot | 15 | 5 Tier A · OSS lowest in matrix | 4 Tier B · OSS base continuity | 1 Tier A · 100% AWS-proprietary | 2 Tier B · own essay: proprietary pipes UI | 4 Tier A · standard portable Kafka |
lines_of_config_lower_better Lower LOC is better | 15 | 3 Tier B · VRL verbose flexible | 3 Tier B · TQL concise for OCSF | 4 Tier B · Glue Studio amortizes | 4 Tier B · own essay: Packs cover most sources | 2 Tier B · per-connector JSON |
resource_efficiency EKS or serverless cost | 10 | 4 Tier B · Rust efficient on EKS | 3 Tier B · C++ EKS hosting | 4 Tier B · Lambda per-execution | 3 Tier B · not as lean as Rust | 2 Tier B · MSK overhead nontrivial |
default_reduction_ratio De-prioritized at C | 10 | 3 Tier B · VRL not default-aggressive | 3 Tier B · less aggressive than Cribl | 3 Tier B · per-source Lambda logic | 4 Tier B · tuned not default | 2 Tier B · pass-through default |
correlation_capability Pipeline-layer correlation | 5 | 2 Tier B · pushes correlation downstream | 4 Tier B · TQL correlation primitives | 3 Tier B · Step Functions chains | 3 Tier B · Cribl Search basic | 1 Tier B · sink only no joins |
aggressive_workload_handling Burst-load behavior | 5 | 3 Tier B · backpressure adaptive | 3 Tier B · buffering reasonable | 3 Tier B · Lambda concurrency cap | 4 Tier B · production-validated burst | 4 Tier B · petabyte-scale by design |
in_house_skill_base Weight-0 convention at C | 0 | null | null | null | null | null |
| Weighted total | 3.55 | 3.40 | 3.35 | 2.95 | 2.75 | |
| Evidence completeness | 1.00 | 1.00 | 1.00 | 1.00 | 1.00 |
Decision shape: no dominant winner; lock-in posture is the pivot
Vector (3.55), Tenzir (3.40), and Firehose+Lambda (3.35) cluster within 0.20 of each other across three genuinely different procurement postures (OSS-on-EKS, commercial-OCSF-on-EKS, fully-AWS-native). The matrix is correctly showing that AWS-committed customers don't have a single right answer here. The mechanical story: pricing (weight 20) × lockin (weight 15) = 35 weighted points concentrated on the C design centers. Vector picks up 100 + 75 = 175 weighted points on those two criteria alone; Firehose+Lambda picks up 100 + 15 = 115; Tenzir picks up 60 + 60 = 120. The 60-point gap from Vector to Firehose+Lambda on lockin is exactly the cost of AWS lock-in priced into the matrix. Tenzir then pulls slightly ahead of Firehose+Lambda on OCSF fidelity (+20 points) and correlation (+5 points), which is offset by Firehose+Lambda's recovery on LOC (+15 points) and resource (+10 points). The net: under Archetype C, the customer's lock-in posture is the decision pivot, not the weighted total. Lock-in-tolerant teams with durable AWS commitment land at Firehose+Lambda, defensible and cheapest; score 1 on lockin doesn't penalize because the customer doesn't care. Lock-in-cautious teams with any multi-cloud roadmap land at Vector or Tenzir. OCSF-fidelity-binding teams (Reg-SCI-style audit requirements) land at Tenzir regardless of the economics.
Where the ranking is fragile
Vector's lock-in 5 depends on Datadog's continued OSS stewardship. If Datadog deprecates or restructures Vector governance, the lock-in score drops to 3 and the weighted total falls from 3.55 to 3.25, placing Tenzir at #1 and Firehose+Lambda at #2. Conversely, a Tenzir Fortune-500 OCSF lossiness reference at < 5% lifts the OCSF score from 4 to 5 (+20 weighted points), bringing Tenzir to ~3.60 and dethroning Vector. The Firehose+Lambda 3.35 is structurally bounded; its lock-in score 1 caps the upside, and even a perfect OCSF transformation path (Lambda+Glue refinement) only lifts the OCSF score by 1 point at weight 20, taking the total to ~3.55, exactly tied with Vector. The "no dominant winner" framing should survive most plausible evidence updates.
Disclosure block. No active partnership disclosures at Pipelines, or anywhere in the standing matrix.
Synthesis · the central architectural finding
Tenzir wins the matrix; Cribl wins the procurement committee.
The 0.40-point gap between Tenzir and Cribl at Archetype A (and the 0.50-point gap at Archetype B) is real on every criterion the matrix scores directly. Tenzir's OCSF-native design, Apache 2.0 core, TQL expressiveness, and pipe-layer detection latency (15–50ms vs. 5–30s) are the architectural facts. I scored what I could measure. But the matrix is also showing an asymmetry it can't encode as a numeric score: production-evidence base. Cribl carries 50+ Fortune-100 production references (vendor-reported, anonymized — Tier B at best), RiverSafe's partner-published 40%-reduction measurement (Tier C, Cribl partner), Yale New Haven Health's 40% Sentinel reduction (a Cribl-published case study, Tier C), and TransUnion at scale. Tenzir's public customer count sits under 100 known deployments with no published Fortune-500 OCSF lossiness audit at 5+ TB/day; that's the A-03 gap.
The honest engagement framing: the matrix scores what's measurable; the procurement-defensibility finding is structural and lives in the qualitative notes. Per A-02-cribl-70-90-is-tuned-not-default, Cribl's marketed 70–90% headline is the aggressive-tuned ceiling, not the out-of-box default; the honest default is 30–50%. I've scored Cribl's default_reduction_ratio at 4 on that adjusted basis, with the shipped-vs-claim delta documented in the YAML. If the H1-COST-02 head-to-head benchmark ships ~Q1 2027 and anchors a Tier-A reduction-ratio measurement, both Tenzir and Cribl's scores on the dominant Archetype-A criterion move at the same time, and the procurement-defensibility framing changes shape with them. Until that benchmark lands, the recommendation pattern is: Cribl is the default for regulated industries where Tier-A practice references gate procurement; Tenzir is the upgrade path when the four conditions in the Archetype A decision shape hold simultaneously.
This is what fair-broker scoring looks like when the matrix and the qualitative finding disagree. I don't collapse them. The matrix tells customers what the criteria say; the qualitative finding tells customers what the procurement committee will say; both are the deliverable.
Synthesis · per-workload selection at Archetype C
Vector 3.55, Tenzir 3.40, Firehose+Lambda 3.35. The right move is per-workload selection.
The 0.20 spread across the top three at Archetype C is too tight to declare a category-wide default. Each candidate fits a different workload shape, and the engagement deliverable should match candidates to workloads rather than recommending a single ingest tier across the customer's full source inventory. Vector's strength is OSS economics at sustained high-volume throughput; its Rust implementation hits 200K rec/sec on the published Huntress reference, and the EKS hosting cost is the only real spend. The weakness is OCSF: every per-source mapping is custom VRL the customer's team has to author and maintain. Recommend Vector for workloads where the schema is already disciplined upstream (well-tagged CloudTrail, Iceberg-friendly app logs) and the team carries VRL expertise.
Tenzir is the right tool for workloads where OCSF fidelity is the binding constraint: multi-source identity correlation, OCSF-conformant detection rule corpora, Reg-SCI-style audit requirements. The TQL correlation primitives at the pipeline layer reduce downstream engine load. The commercial cost ($90–150K/year enterprise tier) is meaningful but defensible against the Cribl per-volume alternative. Firehose+Lambda is the right tool when the customer's AWS commitment is durable (multi-year AWS commit, no multi-cloud roadmap) and the source inventory is AWS-friendly (Tier-1 telemetry that AWS Security Lake's OCSF coverage already handles, plus low-velocity custom sources that fit Lambda's per-execution model). The lock-in score 1 doesn't penalize a customer who's already paying the AWS-lock-in tax for unrelated architectural reasons.
So the practical engagement output for Archetype C is a workload × candidate matrix rather than a single recommendation, with each high-volume source class assigned its own pipeline tier, because a 0.20 spread across the top three sits inside the noise of the modeled cells and forcing one winner out of it would manufacture a confidence the scoring doesn't support.
Cross-component coupling
C4 doesn't decide in isolation.
The pipeline choice depends on the foundation pattern (C0: isolated dedicated vs. shared corporate vs. MSSP), the format and catalog choice (C1+C2: Iceberg+Glue vs. Iceberg+Polaris vs. Delta+Unity), and the visualization tier (C5: Splunk SH federated vs. Grafana on ClickHouse vs. vendor SOC UI). The coupling that matters most for the C4 decision: OCSF normalization can happen at C4 (Tenzir native, Cribl via Packs, Vector via custom VRL) or at C3 query-time (raw events stored, OCSF applied at read via schema-on-read). Both work; the cost shifts. Schema-on-write at C4 trades ingest CPU for query simplicity downstream. Schema-on-read at C3 trades ingest simplicity for query CPU and schema governance discipline.
Cribl's Cribl Search product hints at a third option (schema-on-read at the pipeline layer with operators dispatched against S3-resident raw events), but the Cribl Search architecture requires Iceberg/Delta on S3 and is AWS-aligned, so it interacts with the C0+C1+C2 cascade rather than sitting orthogonal to it. The engagement deliverable scopes the C4 decision against the C0–C2 decisions that have already been made; reversing the order produces churn.
Two caveats worth carrying across that C4/C3 boundary. First, whichever side carries the normalization, it's scored on two levels in order, because the first binds before the second matters. Availability comes first — does the tool ship a usable mapping for the source at all, in the shape the client's actual shipper emits — and first-party pipeline-fidelity work (Tier B, single host, OCSF 1.8.0, version-bound; sdw-lab-benchmarks/pipeline-normalization-fidelity/FINDINGS-2026-06-14.md) found shipped-mapping availability, not per-field fidelity, to be the binding constraint across the open tools tested, with several common security sources having no usable shipped mapping at all, or one bound to a raw input shape (EVTX/XML) that pre-parsed EDR JSON doesn't match. Fidelity comes second, and the gap there is that a shipped mapping can get the OCSF class right and most field values right while still getting the activity classification wrong — "maps to OCSF" is a coverage claim, not a fidelity guarantee, and the part that fails is often the part detection content keys on.
Second, if the C3 side leans on MV-like acceleration (semantic-layer / MV-style transparent query rewrite) to absorb the schema-on-read query cost, remember that it does not move the concurrency knee: the StarRocks-MV upper-bound arm hit the knee at the same ~64× as base StarRocks (2026-06-14 workload-interference bench). "Faster query" is not "helps under load," and materialized views are not a substitute for a concurrency plan.
v1.3 evidence cut · what changed for Pipelines
No Pipelines MDRs were directly affected by today's evidence cut.
The v1.3 evidence sweep moved scores at C1 (Formats) and C2 (Catalogs); the C4 criterion set and weights are unchanged. The one adjacent finding worth flagging: the A-06 Iceberg V3 row-lineage gap could affect a future audit_trail_completeness criterion if I add it in v1.4. Row lineage at the table layer interacts with pipeline-layer transformation provenance; an OCSF-normalized event written to Iceberg loses the raw-event linkage unless the pipeline explicitly persists it. None of the current 9 criteria measures that gap; v1.4 may add it.
Revalidate by 2026-11-25. H1-COST-02 head-to-head benchmark scheduled ~Q1 2027 will be the Tier-A anchor for default_reduction_ratio, aggressive_reduction_ratio, and resource_consumption_cpu_memory simultaneously.
Sibling components, synthesis, and methodology.
Pipelines is one of four primary scoring components. The matrix decisions, assumptions, and methodology pages cover the framework that produces these scores.
Sibling primary product pages
Synthesis and decisions
Decision records and archetypes