The outcome you are walking toward
A complete picture of the mechanism that makes a network of locations more powerful than the sum of its parts: how an improvement discovered in one location is captured, tested, spread, and — when necessary — reversed. The narrative up top is the argument; the mechanics below it are how Franchise OS is designed to run that argument in production. Propagation capability is staged and verified in deployment, not assumed — the institutional deployment path shows where propagation enters an engagement.
Most software decays under scale
More locations create more entropy. More data creates more noise. More tools create more integration tax. The usual outcome of growth is a slower, noisier operation with better dashboards.
MCV.TECH is designed to do the opposite.
Every location is a living node. Every device, every event, every agent action is written into a shared operating record under policy — the evidence model in the audit trail. Every meaningful improvement — a better safety response, a faster service recovery, a more effective coaching cue, a clearer maintenance protocol — can be captured as a versioned playbook.
Franchise OS then evaluates that playbook against real evidence. If it wins, it can propagate. If it fails, it is rejected or refined. If conditions change, it can be rolled back.
The Agents Layer accelerates the loop: ForgeMaster and the vertical specialists are designed to surface candidates continuously, Aria keeps the team coherent, and Sentinel protects the hard boundaries. The physical layer makes the loop real — because the Edge Runtime and the hardware kits keep critical sensing and action alive even when connectivity is imperfect, the organism does not go blind when the network does.
Over time the network stops being a collection of locations that happen to share a brand. It becomes a single compound intelligence designed to get safer, faster, and more effective with every additional node. That is the point of the entire stack: the organism is designed to compound.
The compounding loop
The loop runs locally at every location and across the whole network:
Sense → Decide → Act → Measure → Extract → Evaluate → Propagate → Improve
Sense, decide, act, and measure are the local organism's job. Extract, evaluate, and propagate are what Franchise OS adds on top: the mechanism that turns local excellence into network intelligence. Without it, every location reinvents the wheel. With it, the organism compounds. Everything below is how the second half of the loop is governed.
Playbook anatomy: the versioned bundle
A playbook is a first-class object in the operating record — not a document in a shared drive. Each playbook package is a versioned bundle carrying:
- Identity — a unique ID, version, and digest, so every location runs a known edition.
- Scope — the vertical, location type, brand, legal entity, and geography the playbook applies to.
- Intent and success metrics — what the playbook is for and how winning is measured, written before evaluation begins.
- Trigger conditions — the circumstances under which the playbook activates.
- Agent configuration deltas — which agents change, which parameters move, and under what authority, inside the boundary model described in governed agent boundaries.
- Human procedures and training micro-paths — checklists for staff and the training components owned by Nexus, where the method has a human side.
- Evidence requirements — what must be recorded for the playbook to count as working.
- Rollback conditions — the pre-defined envelope for reverting it.
- Author and approval chain — provenance for every version, end to end.
Playbooks span operational, safety, training, commercial, maintenance, and agent-behavioral changes. What they share is the shape: versioned, scoped, measurable, reversible.
Discovery and nomination: three routes in
Playbooks enter the pipeline through three routes, and every nomination creates a candidate record with full provenance:
- Automatic extraction. ForgeMaster and Cortex are designed to watch for statistically significant positive deviations — faster recovery, lower incident rates, better retention curves, improved labor efficiency at equal or better service levels. When a location or cohort consistently outperforms, the observed method can be nominated as a candidate playbook.
- Human nomination. Operators, trainers, managers, and regional leaders can explicitly nominate a method they believe is superior. Local knowledge enters the same pipeline as machine-found signal.
- Agent-proposed. Specialist agents can propose improvements inside their own domain, subject to the authority they already hold — the model pinned down in the agent authority model.
No route is privileged. A candidate from any route faces the same evaluation.
The evaluation protocol
No playbook is propagated on anecdote. Every candidate moves through the same protocol:
- Baseline capture — the current performance distribution across the relevant network segment is frozen as the baseline.
- Cohort selection — a statistically and operationally sensible set of locations is chosen: size, type, brand, geography.
- Controlled activation — the candidate activates only on the cohort, with a clear start time and monitoring from the first action.
- Measurement window — pre-defined metrics are tracked with the same instrumentation that runs the rest of the organism.
- Guardrails — automatic pause if safety, guest or member experience, or financial metrics degrade beyond thresholds.
- Evidence package — at the end of the window, a complete package is produced: metrics, agent traces, human feedback, anomalies.
The evidence package is the only currency a propagation decision accepts. Candidates that cannot produce one do not move.
Decision and governance: the impact matrix
Propagation authority scales with impact, and high-impact playbooks are never fully automatic:
- Low — minor threshold tuning: automated or regional decision authority.
- Medium — regional decision plus vertical specialist review.
- High — safety, major service model, or agent authority changes: central governance with human approval.
- Critical — explicit multi-party approval and a staged rollout.
Franchise OS records the full decision, including dissenting views and conditions, in the same record that governs everything else. A decision that cannot be reconstructed was not a decision.
Propagation mechanics: staged, reversible, governed
Once a candidate is approved, propagation is a controlled configuration change — not a custom integration project — because agents and edge nodes already speak the same package language:
- The playbook is marked approved for propagation, and the target segment is defined — all locations, a brand, a region, a location type.
- A rollout strategy is chosen: staged waves, or canary then expand. All-at-once rollout is the rare exception, not the default.
- Each location receives the playbook through the normal policy and package distribution channel, and local edge and agents activate the new version under the existing authority model.
- Adoption and effect are monitored network-wide, and the rollback envelope remains armed for the defined period.
Local legitimate variation survives this process: propagation sets the default inside policy, it does not erase context.
Rollback as a first-class command
Every propagated playbook carries an explicit rollback envelope:
- Metric thresholds that trigger an automatic pause.
- A manual kill switch, regional and global.
- Time-boxed automatic review.
- Reversion to the previous known-good playbook version.
Rollback is a first-class, audited command — recorded, attributable, and rehearsed, not an emergency improvisation. Sentinel holds elevated rights to pause safety-related playbooks without waiting for a committee.
Learning across verticals
Most playbooks are vertical-specific. Where a method genuinely transfers — access control patterns, safety observation methods, labor forecasting techniques — Franchise OS supports controlled cross-vertical learning. Cross-vertical candidates face a higher governance bar than same-vertical ones, because the evidence travels further from its context.
Non-goals: what propagation refuses to do
The mechanism is defined as much by what it refuses:
- No automatic propagation of unvalidated changes. Extraction proposes; evaluation decides.
- No one-size-fits-all mandates. Scope is part of the playbook, and local context is a legitimate reason for variation.
- No silent overwriting of local variation. Changes arrive as versioned packages with provenance, visible in the operator console, never as silent drift.
- No propagation without evidence and rollback capability. A playbook that cannot be measured and cannot be reverted does not ship.
Local autonomy is preserved; network intelligence is added on top under governance. That is the whole design — and it is the standard to hold us to in diligence, through the diligence resources path.
