AttestaTrust Intelligence InfrastructurePilot scope and pricing

How Attesta works

The mechanism, the operating model, and who controls what.

Illustrated walkthrough · 39s

The mechanism, end to end

One organization-controlled record, private institutional criteria, and a permission layer that says who can see what.

Captions on
Email thread
no date
Shared drive
version 3
Last year's review
14 months
PDF attachments
source unclear

1/5 Each institution rebuilds the same organizational picture from the beginning.

Read-aloud is not available in this browser. The captions and transcript carry the same words.

What changes in the work itself
Before Attesta — one renewal, today

Four people rebuild context that already existed

  1. 1Analyst

    Searches inbox, shared drive, and last cycle's folder for the most recent financials, board list, and insurance certificate.

    Left behind: A local folder nobody else can find next cycle.

  2. 2Program officer

    Emails the organization a document request that largely repeats last year's, because nobody is sure what is still current.

    Left behind: A thread. The organization re-sends what it already sent.

  3. 3Reviewer

    Rebuilds the assessment in a spreadsheet copied from the last one, with criteria that live in someone's head.

    Left behind: A spreadsheet version with no origin for any number.

  4. 4Committee

    Reads a memo assembled by hand the week before, and asks where two figures came from.

    Left behind: A decision whose basis is hard to reconstruct a year later.

The work is real, but almost none of it accumulates. Next cycle starts here again.

With Attesta — the same renewal

The same four people work on one maintained record

  1. 1Analyst

    Opens the organization's maintained record. Every field carries an origin and a date, so what is current is visible without asking.

    Left behind: Nothing to assemble — the record is the working surface.

  2. 2Program officer

    Sees only the gaps the institution's own lens marks as missing or stale, and requests exactly those.

    Left behind: A receipted request, visible to both sides, scoped to the gap.

  3. 3Reviewer

    Reviews privately against written criteria and thresholds the institution configured once, not re-derived per deal.

    Left behind: A private review attached to the record, reusable next cycle.

  4. 4Committee

    Reads a summary generated from the same record, with each material claim traceable to its origin and date.

    Left behind: Decision history that survives staff turnover.

The same hours produce something the next cycle can start from.

Structural comparison, not a measured result. How many hours this displaces for your team is one of the things a pilot is designed to find out, using your baseline rather than ours.

How your team would operate it
01
Portfolio onboarding
Portfolio manager, with founder support during a pilot

You name the organizations already in your portfolio or pipeline and invite them. Each one maintains a single record; you never re-key their data yourself.

Your existing network, enrolled — not a new network to source.

02
Decision lens
Underwriter, program officer, or procurement lead

You write down what your decision actually requires: fields, evidence, thresholds, and how fresh each must be. The lens reorganizes the same record for your decision without changing anyone else's view of it.

Your criteria, encoded once instead of re-derived per deal.

03
Private review
Reviewers and committee members

Reviews, notes, scores, and internal comparisons stay inside your institution. Organizations see that a review is happening and what was requested — never your assessment of them.

A review attached to the record, not to an inbox.

04
Refresh and change visibility
Analyst — mostly passive

Fields age against the refresh windows you set. Missing, expiring, and changed evidence surface between cycles, with a diff and a date, instead of at application time.

Fewer surprises at decision time; requests scoped to real gaps.

05
Committee-ready output
Whoever writes the memo

A summary generated from the same record, with provenance and dates on every material claim, plus an exportable audit trail of who asked for what and when.

A decision that can be explained a year later by someone who was not there.

The loop repeats per cycle. Steps 01 and 02 are one-time setup work per institution; steps 03 to 05 are the recurring operating rhythm.

What it changes for each person involved
Grantmaking · relationship-owning

Program officer

What changes day to day
  • Pick a grantee relationship back up without re-reading a year of email to remember where it stood.
  • Ask only for what is actually missing or out of date, so the relationship spends less of its goodwill on paperwork.
  • Carry context across a portfolio handover instead of losing it when someone leaves.
The objection this role raises

My grantees are already over-surveyed. This is one more portal.

The organization maintains one record and admits institutions to it. If they already keep it for another funder, your request costs them a permission grant, not a new intake form.

Why not spreadsheets, a portal, or the CRM you already have
Architectural capability comparison between spreadsheets, one-off portals, generic CRMs, institution-specific systems, and Attesta today.
CapabilitySpreadsheets & shared drivesOne-off intake portalsGeneric CRMInstitution-specific systemsAttesta (today)
Organization maintains one record it ownsThe counterparty updates it once instead of refilling each institution's form.Spreadsheets & shared drives: Organization maintains one record it owns: noOne-off intake portals: Organization maintains one record it owns: noGeneric CRM: Organization maintains one record it owns: noInstitution-specific systems: Organization maintains one record it owns: noAttesta (today): Organization maintains one record it owns: yes
Same record readable by several institutionsReuse across institutions without re-collection.Spreadsheets & shared drives: Same record readable by several institutions: noOne-off intake portals: Same record readable by several institutions: noGeneric CRM: Same record readable by several institutions: noInstitution-specific systems: Same record readable by several institutions: noAttesta (today): Same record readable by several institutions: yes
Per-institution decision lens over shared dataEach institution's required fields and thresholds, applied to the same underlying record.Spreadsheets & shared drives: Per-institution decision lens over shared data: noOne-off intake portals: Per-institution decision lens over shared data: partial or variesGeneric CRM: Per-institution decision lens over shared data: partial or variesInstitution-specific systems: Per-institution decision lens over shared data: yesAttesta (today): Per-institution decision lens over shared data: yes
Field-level provenance and recencyWhere a claim came from and when it was last true, carried with the field.Spreadsheets & shared drives: Field-level provenance and recency: noOne-off intake portals: Field-level provenance and recency: noGeneric CRM: Field-level provenance and recency: noInstitution-specific systems: Field-level provenance and recency: partial or variesAttesta (today): Field-level provenance and recency: yes
Organization-controlled, revocable accessAccess is granted by the organization and can be withdrawn, with a receipt.Spreadsheets & shared drives: Organization-controlled, revocable access: noOne-off intake portals: Organization-controlled, revocable access: noGeneric CRM: Organization-controlled, revocable access: noInstitution-specific systems: Organization-controlled, revocable access: noAttesta (today): Organization-controlled, revocable access: yes
Append-only audit trail as a by-productChange and access history that cannot be edited after the fact.Spreadsheets & shared drives: Append-only audit trail as a by-product: noOne-off intake portals: Append-only audit trail as a by-product: partial or variesGeneric CRM: Append-only audit trail as a by-product: partial or variesInstitution-specific systems: Append-only audit trail as a by-product: yesAttesta (today): Append-only audit trail as a by-product: yes
Between-cycle staleness surfacingExpiring and missing evidence appears without someone chasing it.Spreadsheets & shared drives: Between-cycle staleness surfacing: noOne-off intake portals: Between-cycle staleness surfacing: noGeneric CRM: Between-cycle staleness surfacing: partial or variesInstitution-specific systems: Between-cycle staleness surfacing: partial or variesAttesta (today): Between-cycle staleness surfacing: yes
Private institutional review notesNever visible to the organization or to another institution.Spreadsheets & shared drives: Private institutional review notes: partial or variesOne-off intake portals: Private institutional review notes: noGeneric CRM: Private institutional review notes: yesInstitution-specific systems: Private institutional review notes: yesAttesta (today): Private institutional review notes: yes
Secure in-product document uploadAttesta stores evidence metadata only today; files are exchanged out-of-band.Spreadsheets & shared drives: Secure in-product document upload: yesOne-off intake portals: Secure in-product document upload: yesGeneric CRM: Secure in-product document upload: yesInstitution-specific systems: Secure in-product document upload: yesAttesta (today): Secure in-product document upload: no
Automated data integrations / connectorsNone are built in Attesta today. Records are built from documents you already hold.Spreadsheets & shared drives: Automated data integrations / connectors: noOne-off intake portals: Automated data integrations / connectors: partial or variesGeneric CRM: Automated data integrations / connectors: yesInstitution-specific systems: Automated data integrations / connectors: partial or variesAttesta (today): Automated data integrations / connectors: no
Independent security certificationAttesta holds none and none is in progress.Spreadsheets & shared drives: Independent security certification: noOne-off intake portals: Independent security certification: partial or variesGeneric CRM: Independent security certification: yesInstitution-specific systems: Independent security certification: yesAttesta (today): Independent security certification: no

Columns describe common alternative architectures generically, not any named vendor. Ticks describe structural capability, not speed, accuracy, or cost — Attesta has no measured outcome to compare against. Where Attesta lacks something, the row says so.

None of those tools are wrong; they are just built to record a decision, hold an application, or track a relationship — not to keep the underlying evidence current between cycles. Attesta sits underneath them and exports into them.

How the mechanism works
Organization
One maintained record

The organization owns and updates a single structured record: identity, governance, financials, capacity, compliance, and impact — each field carrying its origin and the date it was last true.

Organization controls
Controlled access grant

Nothing is public. The organization grants a named institution read access to the record, sees exactly what was asked for and by whom, and can revoke the grant at any time.

Institution
Decision lens

The institution reads that same record through its own lens — its required fields, evidence, thresholds, and refresh windows. Review notes and criteria stay private to the institution.

Both sides, all year
Refresh and audit

Missing, expiring, and stale fields surface between cycles. Every change, grant, and review is written to an append-only trail, so the audit record is a by-product rather than a project.

The loop repeats without a new application packet. Attesta never introduces counterparties, never ranks organizations, and never moves money — it maintains the record and governs who may read it.

What the product actually looks like
Demonstration — illustrative data
Organization · record field
Audited financial statements
FY2025 · unmodified opinion
CurrentEvidence on file (metadata only)
OriginOrganization-provided
Last confirmed14 days ago
Next refresh duein 351 days
Every field carries origin, evidence, and recency. Evidence is metadata only in this prototype — no files are stored.
Institution · network roster
Riverbend Community Housing92%
Ready for review
Eastside Workforce Collective64%
Incomplete
Harbor Youth Services38%
Not started
2 fields expire within 30 days
Readiness against the requirements this institution defined, recalculated as organizations maintain their records.
Institution · private evaluation
Private to your institution
GovernanceMeets criteria
Financial positionMeets criteria
Operating capacityFollow-up requested
Reviewer note and decision recommendation stay inside the institution. Attesta does not score, rank, or share evaluations with anyone else.
Criteria, notes, and decisions are visible only inside the reviewing institution.
Two sides, one record
For institutions

Decisions that hold up, cycle after cycle

  • Define what a decision requires once — fields, evidence, thresholds, refresh window.
  • Review privately: notes, criteria, and scoring never leave your institution.
  • Pick a relationship back up without restarting diligence from zero.
  • The audit trail is a by-product of the work, not a separate exercise.
For organizations

Answer once, stay visible year-round

  • One record instead of re-keying the same financials into every funder's portal.
  • You decide which institutions can see it, and you can revoke access at any time.
  • See exactly what each institution asked for, and by whom.
  • Free for organizations. No public directory, no inbound solicitation.
Why institutions would keep it after the pilot
Decision history accumulates

Every review, request, and refresh is attached to the record. After two cycles the institution holds a written account of how it decided and why — the thing that is impossible to reconstruct from a spreadsheet after the analyst leaves.

Reverting means starting that history at zero again.

Records are reusable, not per-deal

The work of getting one organization decision-ready is done once and is still there at the next renewal, the next facility, the next grant cycle. The second decision about the same organization costs materially less than the first.

Spreadsheets restart per cycle by construction.

Access is governed, not emailed

Organizations grant scoped, revocable, receipted access. Once legal and risk have accepted that model, moving the same evidence back into attachments and shared drives is a step backwards they have to justify.

Email and drives cannot show who saw what, when.

Refresh runs on its own

Expiry windows, staleness flags, and change diffs mean the portfolio stays current between cycles without someone chasing it. That maintenance loop is the part a one-off portal or an intake form never provides.

Manual chasing resumes the day it stops.

Reconstruction cost falls as the network fills

Each organization an institution enrolls, and each institution an organization admits, reduces how much has to be rebuilt next time. The value is in the maintained layer, which only exists if someone keeps maintaining it.

Leaving forfeits the maintained layer, not just a login.

Stated as the argument, not as evidence: no institution has completed a pilot or renewed yet. Whether these hold for your team is exactly what a bounded pilot is meant to settle, and the outcome memo says so either way.

These are structural arguments, not achieved positions. None of them is proven yet — the pilots are how we find out. Read the full wedge and expansion path.

Who is behind it
Founder-led validation

Institutional conversations, demos, and pilot scoping are intentionally founder-led during validation, so feedback reaches product decisions directly.

Direct early onboarding

Early institutions and organizations will be onboarded by hand, one at a time, so the workflow is shaped against real decisions rather than assumptions.

Founder-designed infrastructure

The architecture, record model, permissions, decision lenses, and operating thesis are founder-directed and founder-designed.

What is functional, and what is illustrative

The private workspace is built and running

Accounts, records, invitations, and access control are implemented and enforced in the database — you would only ever see the institutions and organizations you belong to, and institution workspaces are approved by hand before they can invite anyone. That is working infrastructure, not evidence of adoption: Attesta has no onboarded institutional customers yet, and the first pilots are how that gets tested.

Request a bounded pilot
Two lanes, never mixed

The guided lens paths are a demonstration on invented data, banner-marked on every screen. No organization shown in them is real, and nothing in them reads from or writes to the live database.

Read the full validation status