Retirement-Plan Compliance Engine
State retirement mandates are spread across official websites and statutes, and each state asks different questions. The engine gives compliance staff a governed way to maintain those rules, then lets IRALOGIX products run employer sessions against an exact approved version.
- Tech stack
- Python · FastAPI · PostgreSQL · Event sourcing · OAuth2/OIDC · Auth0 · Kubernetes
- Operating context
- 20+ state programs in scope · Portal + API in the Studio environment · Five-person CMU team, no production traffic
- Role
- Team Lead and system architect, five-person CMU Studio team
- Ownership
- Product discovery, review workspace, rule registry, session engine, and client integration boundary.
System context
Selected ownership
Product direction under ambiguity
Led product discovery from ambiguous requirements to a shared product direction, aligning client stakeholders and a newly formed five-person team on an integration-ready platform architecture.
Governed rule review
Architected the source-to-review lifecycle and built the review workbench: AI-assisted ingestion can stage a source-linked bundle, but only an attributed compliance decision can activate it.
How one rule stays traceable
employee_countRULE MODEL
Versioned valueheadcount_threshold: NStores the interpreted fact used by the engine.
DECISION GRAPH
Question and gateask employee_countReferences the value instead of copying it into flow logic.
CONTENT CATALOG
User-facing wordingemployee_count.promptVersions wording and locale separately from rule behavior.
PROVENANCE
Source evidencerule path + citationConnects the interpretation to its URL and quoted source.
Event-sourced employer sessions
Designed and implemented the API-to-engine session path: append-only answers are projected against a pinned rule bundle, enabling resume, rewind, and fork without mutating prior history.
Append-only session history
Authenticated integration boundary
Designed one API boundary for human, agent, and system clients, with separate JWT trust paths, client-scoped authorization, and signed outbound webhooks.
Two trust paths, one authorization model
IRALOGIX sponsors this year-long CMU Studio project. I lead product direction and architecture and built major engine, API, and Portal slices on a five-person student team; this page does not imply sole authorship. The system runs in a Studio environment and has no production traffic. Dashed elements are designed or integration paths, not launched product behavior.