candidate
approved for public review
Approved for public review as a non-effective draft; no contract or payment obligation is created.
Recorded for KC Streich
AIWI-SOW-001 · version rev-b
A prospective, non-retroactive, milestone-based draft scope for Five Letter Agency implementation and managed operations, subject to related-party and acceptance controls.
candidate
approved for public review
Approved for public review as a non-effective draft; no contract or payment obligation is created.
Recorded for KC Streich
treasurer
pending
Required before financial effectiveness or Committee-to-FLA payment.
legal / compliance
pending
Candidate-owned vendor structure remains subject to the draft's external-review conditions.
Korey Streich Campaign Committee / Five Letter Agency - SOW No. 001 Rev. B
Statement of Work No. 001 - Revision B
Complete AI for Wisconsin Open Civic Operating System, Know Your Neighbor, Public Website, Verifiable Polling, Infrastructure, Open-Source Release, and Managed Operations
Client: Korey Streich Campaign Committee (the Committee)
Contractor: Five Letter Agency, a sole proprietorship of Korey Streich (FLA)
Registered committee locator: Wisconsin Sunshine registrant 1148727
Status: Draft for treasurer approval and Wisconsin Ethics Commission or qualified Wisconsin campaign-finance counsel review
Draft date: July 25, 2026
Program budget reference: AI for Wisconsin Full Technology Program Funding Plan - $150,000 maximum campaign goal
Financial effective date: The date all conditions in Section 20 are satisfied and the last authorized party signs. This SOW is prospective and is not retroactive.
Supersession: This Revision B replaces Revision A, which covered a narrower build, launch, hosting, and operations package.
Related-party disclosure: Korey Streich is both the candidate represented by the Committee and the proprietor of FLA. The Committee's treasurer or an authorized successor must independently approve scope, pricing, milestones, invoices, acceptance, change orders, and payments. The candidate/FLA owner may confirm technical delivery but may not be the Committee's sole financial approver. The Committee's public fundraising goal is not an automatic entitlement or payment obligation to FLA.
1. Purpose
FLA will complete and operationalize the versioned AI for Wisconsin campaign technology program described in the governing campaign architecture and the Know Your Neighbor investigation. The engagement is intended to produce a coherent, public-facing, open-source civic operating system rather than a sequence of unrelated prototypes.
The complete program includes:
1. the Hermes-based AI for Wisconsin public representative and isolated steward and automation profiles;
2. deterministic Campaign Core authority for identities, consent, goals, proposals, ballots, approvals, finances, events, and audit records;
3. accessible public web experiences for campaign information, participation, deliberation, polling, receipts, results, transparency, and account controls;
4. Know Your Neighbor (KYN) as a separate claim-based civic identity, credential, attestation, challenge, appeal, and eligibility service;
5. privacy-preserving poll authorization, ballot handling, deterministic tallies, and public audit artifacts;
6. campaign knowledge, memory, source provenance, goals, outreach, milestones, connectors, and transparency workflows;
7. sovereign and reproducible infrastructure using approved self-hosted and hosted resources;
8. open-source publication, documentation, verification tools, contribution rules, and deployment materials;
9. security, privacy, accessibility, recovery, abuse testing, pilot support, and independent review readiness; and
10. a bounded period of managed operations, stabilization, incident response, and transition support.
The work is governed by explicit capability gates. Code existence alone does not establish production, privacy, legal, accessibility, security, or consequential-use readiness.
2. Meaning of "complete implementation"
For this SOW, complete implementation means completion of the fixed baseline requirements and work packages identified in:
the AI for Wisconsin normative architecture documents in the authoritative campaign repository;
the implementation and acceptance workstreams summarized in Schedule B;
the KYN investigation, architecture, schemas, threat model, phases 0 through 5, and agent-ready work packages summarized in Schedule C;
the public website and interface scope in Schedule D;
the production infrastructure, operations, and transition scope in Schedule E; and
approved written clarifications adopted before the financial effective date.
Complete implementation does not mean unlimited future feature development, indefinite operations, automatic compliance certification, guaranteed statewide adoption, or implementation of a governmental system after the campaign. System amendments approved after the baseline may be funded only from the Committee-held contingency reserve or a separately approved change order, without increasing the public $150,000 program goal.
3. Existing work and non-retroactive treatment
Development began before this SOW. The parties will not backdate the agreement or create a fictional prior obligation.
1. Schedule A must identify the baseline date, repository commits, deployed artifacts, accounts, hardware, documentation, and known implementation status existing before financial effectiveness.
2. Pre-effective work is Background Material and is not automatically compensable under this SOW.
3. The treasurer and compliance reviewer will separately classify any earlier campaign benefit as uncompensated personal service, qualifying Internet activity, an authorized in-kind contribution, or another lawful category.
4. No milestone may pay FLA for work substantially completed before the effective date unless the milestone is prospectively replaced with additional defined deliverables of equivalent approved value.
5. The fixed fee compensates only the future completion, integration, productionization, testing, documentation, release, launch, and handoff obligations accepted under this Revision B.
6. Existing FLA or Party Party general-purpose technology remains Background IP unless Schedule A expressly assigns or licenses it.
4. Organizational and data boundaries
The following contexts remain legally, financially, technically, and operationally distinct:
| Context | Primary role | Prohibited merger |
|---|---|---|
| Korey Streich Campaign Committee | Candidate committee, campaign communications, campaign funds, candidate commitments, campaign polls | No automatic access to Party Party customer data, KYN evidence, or secret ballots |
| AI for Wisconsin | Public campaign identity and campaign operating system | Not a separate legal person or financial account unless lawfully established |
| Five Letter Agency | Related-party vendor, technical operator, and owner of general reusable technology | Campaign funds may not capitalize unrelated FLA products or pay general personal/business overhead |
| The Party Party | Separate media, civic-technology, and commercial context | Patronage or purchases may not create campaign voting rights, KYN assurance, or donor status |
| Know Your Neighbor | Separate claim, credential, attestation, and eligibility trust service | KYN may not expose raw identity/evidence to Hermes, campaign marketers, Party Favors, or ballot records |
| Party Favors/gamification | Non-governance participation and recognition layer | Points, ranks, purchases, or engagement may not change voting weight or credential assurance |
Shared leadership does not merge funds, accounts, credentials, authority, data, privacy notices, or public statements.
5. Workstream 1 - Baseline, governance, contracts, and program control
FLA will:
reconcile the current repositories and deployments against the authoritative architecture;
create the dated Background Material and Background IP inventory;
establish requirements traceability from every accepted requirement to code, policy, test, owner, and acceptance evidence;
finalize architecture-decision records for organizational ownership, trust boundaries, data classes, keys, credentials, polling, KYN, gamification, licensing, and infrastructure;
maintain a decision, risk, dependency, change, and acceptance register;
produce machine-readable work packets for authorized AI agents and human contributors;
maintain explicit status labels: planned, in progress, implemented, tested, deployed, accepted, blocked, or retired;
define a no-retroactive-billing and related-party approval workflow; and
maintain a public-safe program status view without exposing restricted campaign or participant information.
Acceptance: The treasurer and technical reviewer confirm that the baseline prevents retroactive billing, hidden scope, undocumented account ownership, or payment for materially completed work.
6. Workstream 2 - Sovereign infrastructure, security, backup, and recovery
FLA will implement the approved campaign production topology using the Pi 5, OptiPlex, and/or campaign-approved hosted services. This includes:
hardened supported operating systems, service accounts, SSH controls, firewalling, time synchronization, and asset inventory;
encrypted SSD-backed authoritative storage rather than microSD for durable campaign records;
UPS-backed orderly shutdown and restart where self-hosted state is authoritative;
private service networks and authenticated public ingress;
reverse proxy, DNS, TLS, certificate renewal, and origin protection;
separate container or service identities, secrets, database roles, and key boundaries;
PostgreSQL, Keycloak, Campaign Core, KYN, Hermes profiles, memory services, web services, queue/workers, object/evidence storage, monitoring, and backup jobs as approved;
encrypted off-device and geographically separate critical backups;
clean-host restore, point-in-time recovery where approved, and post-restore reconciliation;
monitoring and alerting for service health, disk, backup age, certificates, queues, connector lag, and public audit publication;
protected deployment and rollback procedures;
denial-of-service, rate-limit, and accessible fallback controls;
a private runtime inventory and public-safe deployment manifest; and
replacement, migration, and service-exit procedures.
The Committee will not pay an estimated percentage of FLA's general office, household Internet, rent, utilities, or mixed-use equipment. The Committee purchases defined campaign services and campaign-specific assets or actual documented provider costs.
7. Workstream 3 - Campaign Core and deterministic authority
FLA will complete Campaign Core as the typed, deterministic authority for consequential campaign operations. The work includes:
principals, organizations, external identities, roles, capabilities, participation tiers, grants, and revocation;
consent, visibility, retention, correction, export, deletion, and provenance;
append-only events, immutable versions, transactional outbox, idempotency, durable jobs, retries, dead letters, and rebuildable projections;
goals, dependencies, metrics, candidate acceptance, obligations, amendments, overrides, and outcomes;
outreach targets, attempts, appearances, evidence, funnel measures, and follow-up states;
proposals, deliberation, ballots, eligibility, authorization, votes, receipts, challenges, and deterministic tallies;
milestone and unlock evaluation, approvals, expiration, rollback, and execution evidence;
finance import/reconciliation interfaces, commitments, liabilities, restricted data, and treasurer approval boundaries;
knowledge and publication state, connector cursors, and signed public snapshots;
OpenAPI, JSON Schema, event, and client contracts shared by backend, plugins, workers, and web applications; and
complete unit, property, migration, authorization, replay, concurrency, and integration tests.
No connector, web client, or Hermes prompt may duplicate or override authoritative business rules.
8. Workstream 4 - Identity, consent, privileged access, and organization separation
FLA will complete:
passkey-capable privileged authentication and recovery;
Keycloak realms, clients, service identities, strict token verification, and subject binding;
participant account onboarding that does not misrepresent account control as identity, residency, or eligibility proof;
candidate, treasurer, steward, reviewer, privacy, security, automation, and service-role administration;
exact grants, expirations, reauthentication, dual approval, and revocation for protected actions;
consent and retention displays tied to exact policy versions;
correction, export, deletion, recovery, and transfer workflows;
cross-organization access denial and explicit transfer/grant records; and
complete negative-path evidence for every protected operation.
9. Workstream 5 - Hermes runtime and public AI integration
FLA will complete and operate the pinned Hermes integration without granting model authority over campaign records.
9.1 Public profile
The aiwi-public profile will support approved public web, Discord, voice, and future channel interactions with:
source-backed campaign explanations;
clear identity and authority notices;
low-risk questions and listening;
deterministic handoffs for confirmed public input, account, KYN, poll, receipt, correction, and contact workflows;
language and accessibility support where approved;
scoped local or provider model routes based on data class; and
no raw terminal, filesystem mutation, arbitrary code, credential administration, unrestricted browser/network access, direct database access, or financial execution.
9.2 Steward profile
The isolated aiwi-steward profile will support authorized research, review, preparation, candidate work, approval queues, deployment assistance, and private continuity without being reachable from public channels.
9.3 Automation profile
The isolated aiwi-automation profile will support approved scheduled summaries, connector synchronization, source and milestone checks, audit package preparation, backup/health checks, and other bounded recurring jobs under service identities.
9.4 Campaign plugin and tools
FLA will complete the standalone aiwi-campaign plugin, profile-specific skills, hooks, memory providers, and exact tool contracts. Every consequential tool must:
resolve the calling principal and organization;
fail closed independently of model or hook behavior;
require exact capability and policy version;
separate prepare, confirm, execute, and receipt states;
produce immutable audit evidence; and
avoid exposing raw KYN evidence, ballot selections, secrets, or unrestricted APIs to the model.
10. Workstream 6 - Knowledge, provenance, wiki, and memory
FLA will implement:
versioned canonical Markdown and source manifests;
ingestion, parsing, full-text and derived semantic indexes;
source identity, exact version, freshness, status, and claim provenance with material answers;
reviewable correction and revision workflows;
a public wiki rendered from approved canonical material;
consent-aware public participant memory;
private steward memory with campaign retention rules;
invalidation of embeddings, summaries, caches, and memory when sources or consent are removed; and
safeguards preventing agent memory, participant statements, or unapproved sources from becoming official campaign facts.
11. Workstream 7 - Connectors, outreach, goals, milestones, and transparency
The complete baseline includes supported integrations for:
Discord;
campaign Gmail;
campaign Google Calendar;
X/Twitter where available and lawfully approved;
YouTube;
Reddit;
campaign website forms and privacy-preserving analytics;
approved campaign-finance import or reconciliation input; and
manual evidence adapters where a platform does not expose the needed operation lawfully through an API.
Each connector must have least-privilege credentials, organization ownership, source-native IDs, cursors, idempotency, raw-payload retention rules, retries, dead letters, health, and revocation.
FLA will also complete:
the versioned campaign goal graph and candidate-obligation system;
Wisconsin, national, and international outreach tracks kept separately measured;
proposal, appearance, publication, follow-up, and outcome evidence states;
metrics that do not conflate reach, engagement, support, stated intent, and completed votes;
milestone and unlock packets with cost, risk, authority, expiry, rollback, and approval requirements; and
signed, redacted public transparency releases and independent verification tools.
12. Workstream 8 - Know Your Neighbor Trust Service
FLA will implement KYN as a separate, open-source, claim-specific trust service operated under distinct policies, databases, keys, credentials, and administrative roles.
12.1 Core claim and credential system
The system will support separately versioned claims for:
unique human participant;
age or elector eligibility predicates;
Wisconsin residency;
municipality, district, ward, ZIP, or other poll-relevant geography at the least necessary granularity;
registered-voter status where a poll lawfully requires it;
organizational or community membership;
direct personal knowledge, introduced connection, or other relationship evidence;
professional, institutional, lived-experience, or demonstrated expertise; and
continued validity, expiration, revalidation, suspension, revocation, and supersession.
12.2 Attestation graph
FLA will implement:
direct, introduced, institutional, evidence-based, and adjudicative evidence categories;
non-transitive trust by default;
multiple independent paths where policy requires them;
attestor caps, velocity limits, cluster/ring indicators, random audits, and claim-specific authority;
privacy-limited relationship and introduction records;
accessible pathways for participants without strong conventional identity documents or social networks;
challenge, response, reviewer assignment, recusal, decision, appeal, and receipt workflows; and
downstream review rules when an attestor or issuer loses authority.
No visible universal social-credit score will be created. Verifier reliability applies only to verification actions and cannot depend on political views, popularity, patronage, wealth, Party Favors, or general platform engagement.
12.3 Privacy and evidence boundary
FLA will implement:
pairwise pseudonymous subject identifiers;
separate KYN, evidence, authorization, ballot, and reward trust domains;
short-lived and minimal evidence handling;
no routine retention of government-ID images, biometrics, full dates of birth, or exact addresses when a predicate or derived jurisdiction claim suffices;
an encrypted Evidence Vault for exceptional case-scoped materials;
field-level minimization, retention, access, correction, deletion, and breach-containment controls;
key separation, rotation, revocation, and recovery;
privacy-safe audit logs that do not reconstruct political choices; and
credential formats compatible with later W3C Verifiable Credentials and OpenID credential issuance/presentation profiles without requiring a wallet in the initial pilot.
12.4 KYN phases and gates
The deliverable includes the capability gates defined by the KYN plan:
| Phase | Required result |
|---|---|
| Phase 0 | Approved policy, architecture, threat model, schemas, legal/privacy decisions, and infrastructure gate |
| Phase 1 | Synthetic/consenting prototype with deterministic claims, attestations, cases, credentials, and mock polling |
| Phase 2 | Limited trusted-verifier falsification pilot with seeded abuse cases, audits, inclusion tests, and published findings |
| Phase 3 | Verified nonbinding polling pilot with separate tallies, receipts, challenge rules, and public audit package |
| Phase 4 | Expanded geography/expertise credentials and stronger privacy/credential interoperability |
| Phase 5 | Public auditability, broader-load hardening, independent review readiness, and consequential-use gate |
A failed pilot is an accepted research result when documented against precommitted stop conditions. It does not require FLA to conceal failure or preserve a disproven design.
13. Workstream 9 - Poll authorization, ballots, tallies, and public audit
FLA will implement:
signed, immutable poll manifests defining question, options, poll class, constituencies, eligibility, opening/closing, challenge, privacy, tally, and decision effect;
separate open-public, account-bound, self-attested, community-verified, local, affected-community, expertise, campaign, staff, and international tallies as applicable;
one person/one ballot within each declared constituency, with transparent overlap and no hidden engagement weighting;
isolated credential presentation and poll-authorization services;
single-use or privacy-preserving authorization tokens/nullifiers;
ballot storage without identity columns or routine identity-side logs;
exact-choice confirmation, replacement/revote rules, abstention, receipt, challenge, and invalidation;
deterministic tally code, canonical snapshots, code/policy digests, signatures, Merkle proofs or equivalent commitments, and public verifier tooling;
a pluggable path from pilot-grade opaque tokens to blind credentials, Semaphore-like anonymous group proofs, Belenios, or another independently reviewed end-to-end verifiable engine;
trustee/key governance, operator separation, correlation red-team testing, and public witness/mirror support before consequential use; and
system-amendment polls that create exact change obligations but do not automatically deploy code or bypass human/legal release approval.
No result may be described as statistically representative solely because participants were verified.
14. Workstream 10 - Public websites and participant experience
FLA will deliver and operate the campaign's public web surfaces, including ai-for-wi.com and approved campaign subdomains, with:
campaign identity, goals, methods, sources, progress, candidate obligations, and transparent limitations;
accessible campaign contribution links and legally required attribution;
public representative chat and voice handoffs where approved;
proposal, deliberation, poll listing, manifest, eligibility, ballot, receipt, results, and audit experiences;
account, identity, consent, correction, export, deletion, and recovery controls;
public wiki, source, correction, freshness, ledger, deployment, policy, and incident views;
tier-separated tallies and independently verifiable result packages;
campaign/Party Party/KYN operator and financial disclosures;
semantic HTML, keyboard access, visible focus, screen-reader status, responsive behavior, and WCAG 2.2 AA target;
privacy-preserving analytics without advertising pixels, session replay, or political-response targeting on KYN and ballot routes;
deterministic backend-for-frontend boundaries that do not make Supabase, Convex, Vercel logs, or browser storage authoritative; and
complete loading, empty, denied, expired, outage, correction, and recovery states.
The KYN participant and verifier portal may be presented on an approved Party Party-operated domain only when the operator, data controller, financial relationship, and campaign relationship are conspicuously disclosed. Campaign funds may not finance unrelated uspartyparty.com commerce, Patreon, merchandise, sponsorship, or general FLA product development.
15. Workstream 11 - Gamification and reward isolation
FLA will implement a sanitized, one-way reward adapter that may recognize civic learning, participation, attendance, useful submissions, open-source contribution, verification review, or other approved activity without exposing political choices.
The system must prove that Party Favors, subscriptions, merchandise purchases, donations, ranks, badges, popularity, patronage, and engagement cannot:
create additional ballots;
increase ballot weight;
establish KYN personhood, residency, expertise, or reliability;
remove a challenge or audit requirement;
grant access to secret-ballot data;
change official result visibility; or
create campaign or governmental authority.
16. Workstream 12 - Open-source release, documentation, testing, and independent review readiness
FLA will:
publish approved software, schemas, tally/verifier code, safe deployment templates, policies, architecture, prompts or prompt templates, and public knowledge under the approved open-source licenses;
keep secrets, donor data, private strategy, raw restricted logs, evidence, credentials, and protected participant records out of public repositories;
provide pinned dependencies, lockfiles, software bills of materials, reproducible builds, vulnerability and secret scans, and release manifests;
maintain contribution, review, supply-chain, test, and protected-boundary rules;
provide administrator, treasurer, steward, reviewer, incident, backup, restore, key, deployment, and transition runbooks;
provide independent audit/verifier commands and test vectors;
run unit, integration, acceptance, accessibility, threat, abuse, load, restore, correlation, and negative-permission suites appropriate to each phase;
support external legal, privacy, accessibility, and security reviewers with documentation and evidence; and
remediate accepted findings within the fixed scope or approved reserve.
FLA does not furnish an independent legal opinion, independent penetration-test attestation, independent accessibility certification, or independent cryptographic audit. Those functions must be performed or approved by persons who are not merely validating their own work.
17. Workstream 13 - Launch, managed operations, and transition
17.1 Launch and stabilization
FLA will:
execute gated release and migration rehearsals;
complete the approved public, participant, candidate, treasurer, steward, KYN, ballot, and transparency journeys;
record deployed code, policy, schema, model, prompt, key, data, and container versions;
exercise emergency stop, rollback, backup, restore, and service recovery;
publish the approved release manifest and public verification package;
retire superseded production paths; and
provide 30 days of defect-only launch stabilization within the implementation fee.
17.2 Managed operations
After activation and the included stabilization period, FLA may provide up to twelve active service months at $1,000 per month, subject to continued lawful campaign purpose and monthly treasurer approval.
Included operations are:
continued serving of approved campaign web, Hermes, Campaign Core, KYN, poll, audit, and infrastructure services;
routine health and alert review;
backup monitoring and scheduled restore verification;
routine tested security and dependency updates;
DNS, TLS, reverse-proxy, deployment, and provider-account maintenance;
up to four routine approved deployments per month;
credential-expiration tracking and supported rotation;
routine incident triage, containment, recovery, and public-safe record preparation;
bounded connector and queue recovery;
monthly cost, availability, deployment, backup, incident, security, and unresolved-risk record; and
orderly data export, archive, suspension, migration, or transition at the Committee's direction.
This is a low-cost managed campaign platform service, not a staffed 24/7 enterprise service-level agreement. It does not include unlimited feature development, guaranteed uptime, continuous human monitoring, major forensic reconstruction, or governmental operations.
18. Compensation, program budget, and payment controls
18.1 Fixed FLA implementation fee
The proposed fixed fee for future completion of Workstreams 1 through 13 is $72,000, payable only through accepted milestones in Schedule F.
The fee is intentionally reduced for a public-interest, open-source campaign project. It is not a formal fair-market valuation, a promise of development hours, or permission to pay for pre-effective work.
18.2 Managed operations reserve
The Committee may reserve up to $12,000 for no more than twelve active service months at $1,000 per month. No monthly fee accrues before activation or after lawful suspension, termination, or transition.
18.3 Committee-held program reserves
The Committee's proposed $150,000 technology goal includes funds not automatically payable to FLA:
| Program allocation | Maximum | Control |
|---|---|---|
| FLA fixed implementation milestones | $72,000 | Treasurer-approved milestone acceptance |
| FLA managed operations | $12,000 | Monthly activation and service record |
| Campaign infrastructure and provider reserve | $18,000 | Actual documented campaign-specific costs, preferably Committee-owned accounts |
| Independent legal, campaign-compliance, security, privacy, cryptographic, and accessibility review | $20,000 | Committee contracts directly where practical |
| Pilot participation, accessibility, translation, travel, in-person verification, and community operations | $8,000 | Approved actual program costs; no payment for votes or political outcomes |
| Contingency, incident, scale, vendor-change, and approved system-amendment reserve | $20,000 | Not payable without a prospective written approval/change order |
| Maximum technology program goal | $150,000 | Not an automatic spending obligation |
18.4 Fundraising goal is not FLA compensation
Contributions are made to the Korey Streich Campaign Committee. The public funding goal expresses the Committee's intended maximum technology program budget. It does not:
earmark donor funds to FLA;
require the Committee to spend the entire amount;
guarantee FLA the contingency or direct-cost reserves;
permit payment for rejected, incomplete, pre-effective, or out-of-scope work;
remove the treasurer's approval obligations;
allow corporate or otherwise prohibited campaign contributions; or
restrict the Committee from lawfully adjusting expenditures while preserving the public no-upward-revision ceiling.
Unused funds remain Committee funds and must be handled under applicable campaign-finance law and adopted public policy.
18.5 Direct costs
Campaign-specific provider, hardware, domain, API, SMS, email, voice, storage, backup, monitoring, security-key, networking, accessibility, translation, travel, or pilot costs must be:
prospectively approved;
supported by invoices, receipts, metering, or purchase records;
charged without hidden FLA markup unless a separately approved procurement fee is disclosed;
assigned to the Committee directly where practical; and
distinguished from FLA's general overhead, office, household, or unrelated business costs.
19. Milestone acceptance and change control
1. Each milestone requires the evidence listed in Schedule F.
2. FLA submits a delivery packet and invoice only after the deliverable exists.
3. The candidate may attest to technical facts but cannot be the sole financial approver.
4. The treasurer or designated independent reviewer records acceptance, rejection, or conditional acceptance with reasons.
5. Rejected work is corrected within scope before payment.
6. A model, agent, GitHub issue, Discord message, or verbal request does not create a campaign obligation.
7. Every change order states the exact added/removed deliverables, price, funding source, security/privacy/authority impact, and acceptance evidence.
8. Approved change orders draw from the $20,000 Committee-held reserve unless another lawful Committee source is identified; they do not raise the public $150,000 goal.
9. No change may merge KYN identity with ballots, give rewards voting power, grant model authority, weaken legal/financial approval, or waive a system invariant.
10. A material system amendment approved through a public poll still requires campaign authority, legal review where applicable, implementation evidence, and human release approval.
20. Conditions precedent to financial effectiveness
Before this SOW creates a financial obligation:
1. Schedule A identifies the exact Background Material and pre-effective implementation boundary.
2. Schedule B fixes the authoritative campaign architecture and requirements baseline.
3. Schedule C fixes the KYN report/version and accepted ADRs.
4. The Committee treasurer independently approves the related-party relationship, scope, milestone prices, operations rate, direct-cost rules, and acceptance process.
5. The parties obtain written Wisconsin Ethics Commission advice or review from qualified Wisconsin campaign-finance counsel addressing the candidate-owned sole proprietorship, fair pricing, prior work treatment, open-source release, hosting, hardware, and recurring operations.
6. FLA provides a W-9 and ordinary business invoicing information.
7. The Committee confirms it has left any limited-activity reporting exemption as required and can record obligations, disbursements, in-kind contributions, and direct costs.
8. The parties select open-source licenses and record Background IP and campaign-funded IP treatment.
9. The Committee identifies the authorized privacy, security, finance, and acceptance reviewers.
10. No protected participant, donor, financial, KYN, credential, or ballot data is admitted until the corresponding privacy, security, retention, recovery, and access gate passes.
21. Intellectual property and open-source rights
1. Background IP remains with its pre-existing owner unless Schedule A states otherwise.
2. Campaign-funded deliverables must be identified by repository, commit, artifact digest, documentation version, and license.
3. The Committee receives a perpetual right to use, reproduce, modify, host, migrate, and verify accepted campaign deliverables for lawful campaign and archival purposes.
4. FLA will publish approved general-purpose source under the selected open-source license, subject to security and privacy exclusions.
5. Secrets, personal data, donor information, campaign strategy, KYN evidence, restricted logs, private configuration, and ballot data are not public source.
6. Dedicated deployment, configuration, data migration, moderation, hosting, support, incident response, and campaign-specific content remain services even when the underlying source is open.
7. No license may imply that a third party receives campaign authority, official endorsement, participant data, or access to campaign credentials.
22. Security, privacy, legal, and accessibility controls
FLA and the Committee will follow the approved security, privacy, retention, campaign-finance, accessibility, and incident policies. At minimum:
Hermes does not receive raw identity evidence, private keys, donor financial data, or secret ballot selections;
model output is not authoritative merely because it is fluent or confident;
consequential actions use deterministic services, exact authorization, confirmation, and receipts;
campaign donor, Party Party customer, KYN identity, poll authorization, ballot, and reward records remain separated;
third-party analytics and advertising reuse are prohibited on KYN and ballot routes;
privileged actions require phishing-resistant authentication where supported;
public, steward, automation, KYN, evidence, ballot, and finance credentials are isolated;
data fields require documented purpose, granularity, access, retention, correction, deletion, and breach treatment;
participant alternatives, appeals, language, disability, rural, low-bandwidth, and weak-documentation needs are tested;
poll and campaign representations use exact readiness labels and do not overclaim anonymity, security, representation, or legal effect; and
external legal, security, privacy, cryptographic, and accessibility findings are tracked to resolution or a documented stop decision.
23. Explicit exclusions
The following are outside this SOW unless later added within the existing $150,000 program ceiling:
arbitrary features not traceable to the versioned baseline;
indefinite or post-government operations;
a production system for the Office of Governor or another governmental body after election;
general Party Party commerce, Patreon, merchandise, sponsorship, advertising, or unrelated uspartyparty.com development;
unrelated FLA/SIGNET/FACET/KOSMOS product development;
campaign advertising buys, field operations, general payroll, travel, events, or media production unrelated to the technology program;
payment to participants for votes, political positions, attestations, challenges, or outcomes;
raw government-ID or biometric retention as a default product requirement;
guarantees that a social-attestation hypothesis, cryptographic design, vendor integration, legal theory, or pilot will succeed;
guarantees of statistically representative polling without a separately accepted sampling methodology;
guaranteed 24/7 staffing or enterprise uptime;
prohibited contributions, foreign-national election decision-making, or corporate underwriting of candidate-committee activity; and
any work that counsel, the Ethics Commission, the treasurer, or a security/privacy authority determines should stop.
24. Termination, suspension, and transition
The Committee may suspend a workstream or the entire program for illegality, security risk, privacy risk, failed gate, lack of funds, loss of campaign purpose, or material breach.
On termination:
accepted milestones remain payable only if lawfully approved;
unaccepted future milestones do not become due;
FLA provides accepted source, documentation, data exports, deployment manifests, account/credential inventory, and transition materials;
campaign-owned provider accounts and domains remain with the Committee;
FLA-owned general hardware, trade names, subscriptions, and unrelated systems remain with FLA;
secrets and access are rotated or revoked;
data retention, deletion, legal hold, archive, and incident duties continue as applicable; and
the parties publish an appropriate public-safe status and expenditure record.
25. Signatures
For the Committee
Korey Streich Campaign Committee
Authorized treasurer or successor: ______________________________
Name: _________________________________________________
Date: __________________________________________________
For the Contractor
Five Letter Agency
By: Korey Streich, Proprietor: _________________________________
Date: __________________________________________________
Candidate related-party acknowledgment - not payment approval
I acknowledge the related-party relationship, the non-retroactive treatment of prior work, the public funding and disclosure controls, and the requirement that I not act as the Committee's sole financial approver.
Korey Streich: ___________________________________________
Date: __________________________________________________
Schedule A - Background Material, current state, accounts, and IP
Complete before financial effectiveness.
| Item | Required record |
|---|---|
| Baseline date and time | Exact date/time and preparer |
| Campaign repository | Repository, branch, commit SHA, visibility, owner |
| Public website | Repository, deployment, domain, provider, current status |
| Hermes/runtime repositories | Repository, branch, commit SHA, deployment status |
| Infrastructure repository | Repository, branch, host inventory, deployment status |
| Current services | Service, host/provider, account owner, data class, cost payer |
| Current hardware | Device, owner, location, dedicated/shared use, storage, UPS, warranty |
| Current credentials/keys | Identifier and custodian only; never secret value |
| Existing implementation | Workstream and status with evidence |
| Existing open-source material | Repository, license, owner, restrictions |
| FLA Background IP | Component, provenance, license to Committee |
| Committee-funded IP | Component, payment/evidence, ownership/license |
| Pre-effective expenses | Item, payer, date, classification pending/approved |
| Known legal/security/privacy blockers | Exact blocker and responsible reviewer |
Schedule B - AI for Wisconsin baseline workstreams
| ID | Workstream | Completion evidence |
|---|---|---|
| AIWI-01 | Governance, repository, contracts, requirements traceability | Approved ADRs, schemas, source, tests, status register |
| AIWI-02 | Sovereign infrastructure and recovery | SSD/UPS, private networks, encrypted backup, clean restore, alerts |
| AIWI-03 | Campaign Core and event authority | Complete typed services, migrations, events, projections, authorization tests |
| AIWI-04 | Identity, consent, roles, and privileged access | Passkeys, grants, consent, recovery, export/deletion, denial evidence |
| AIWI-05 | Hermes public/steward/automation integration | Isolated profiles, plugin, tools, memory, audit trace, dangerous-tool denial |
| AIWI-06 | Knowledge, provenance, wiki, and memory | Canonical versions, citations, correction, consent invalidation |
| AIWI-07 | Connector fabric | Approved live connectors, cursors, retries, health, revocation |
| AIWI-08 | Goals, outreach, candidate obligations, and funnel | Versioned goals, evidence states, candidate acceptance, public progress |
| AIWI-09 | Participation, deliberation, and ballots | Proposal provenance, immutable ballots, eligibility, receipts, tally |
| AIWI-10 | Milestones, unlocks, approvals, and finance | Evidence-based gates, treasurer workflows, reconciliation boundaries |
| AIWI-11 | Public web application | Complete accessible public and authenticated journeys |
| AIWI-12 | Transparency and public ledger | Signed snapshots, redaction, independent verification, public status |
| AIWI-13 | Security, abuse, migration, and final cutover | Threat tests, incidents, restore, migration reconciliation, release manifest |
Schedule C - KYN baseline work packages
| ID | Deliverable | Acceptance evidence |
|---|---|---|
| KYN-000 | Requirements, glossary, policies, ADRs, privacy impact, threat model | Every requirement mapped to decision and test |
| KYN-010/020 | Service scaffold and relational/event schema | Fresh/upgrade migrations, constraints, typed contracts |
| KYN-030/040 | Account binding, pairwise IDs, claim catalog, policy evaluator | Strict OIDC and cross-relying-party unlink tests |
| KYN-050/060 | Attestation, introduction, challenge, decision, and appeal | Nontransitivity, recusal, receipt, replay, deadline tests |
| KYN-070 | Evidence Vault, encryption, access, and deletion | No model/log exposure; expiry and restore tests |
| KYN-080/090 | Credential issuer, status, verifier authority, caps, risk, audits | Key/status/replay/rotation and seeded graph tests |
| KYN-100 | Accessible participant, attestor, reviewer, and recovery interfaces | Full keyboard/screen-reader/low-bandwidth journeys |
| AIWI-110/120 | Credential verifier and immutable poll manifest/compiler | Canonical hash, issuer denial, immutable-open tests |
| AIWI-130/140 | Authorization exchanger and ballot engine | One-subject rules, separated logs, no identity columns, race tests |
| AIWI-150/AUD-260 | Deterministic tally and public audit/verifier | Clean-machine reproduction and tamper detection |
| AIWI-160/WEB-170/180 | Hermes tools and web handoffs | Capability denial, deterministic confirmation, complete participant journeys |
| PF-190/200 | Reward adapter and civic-vote isolation | No KYN/ballot read or vote-weight path |
| OPS-210/240 | Hosts, keys, backup, logging, correlation controls | Firewall, rotation, restore, prohibited-data scans |
| SEC-250 | Abuse and insider suite | Seeded Sybil/ring/recovery/challenge/token/tally outcomes |
| PILOT-280 | Trusted-verifier and verified-poll pilots | Precommitted criteria, audit sample, redacted public report |
| CRYPTO-290/VC-300 | Verifiable-voting and credential interoperability | Reviewed versions, threat/accessibility/performance evidence |
Schedule D - Public interface and website acceptance
| Journey | Required result |
|---|---|
| Anonymous visitor | Can learn, inspect sources, ask questions, and understand limitations without account |
| Campaign supporter | Can reach the official contribution flow with attribution and no KYN/commerce confusion |
| Returning participant | Can authenticate, inspect consent/status, correct/export/delete applicable records |
| KYN participant | Can request claims, invite attestors, understand evidence, recover, challenge, and appeal |
| Attestor/reviewer | Can perform only authorized, exact, auditable actions with recusal and privacy controls |
| Poll participant | Can inspect manifest, prove eligibility, cast exact choice, receive receipt, verify inclusion |
| Public auditor | Can obtain manifest, snapshots, code/policy digests, signatures, and verifier tooling |
| Candidate/treasurer | Can review obligations, approvals, finance, reconciliation, and publication boundaries |
| Accessibility | WCAG 2.2 AA target, keyboard, screen reader, mobile, low-bandwidth, language and recovery paths |
| Privacy | No advertising/session replay on KYN/ballot; no ballot content in transcripts or general logs |
Schedule E - Operations, providers, assets, and ownership
| Resource/service | Owner | Payer | Data class | Recovery/exit requirement |
|---|---|---|---|---|
| ai-for-wi.com and campaign domains | Committee or recorded lawful custodian | Committee | Public/restricted configuration | Transferable DNS and registrar access |
| Public web deployment | Committee-preferred account | Committee | Public/restricted logs | Reproducible deployment and export |
| Keycloak/Campaign Core | Committee campaign environment | Committee | Restricted authoritative | Encrypted backup, restore, key rotation |
| KYN Trust Core | FLA/Party Party operator under disclosed agreement | Allocated by approved use | Highly restricted identity/credential | Separate export, deletion, revocation, transition |
| Evidence Vault | Approved KYN operator boundary | Approved program cost | Exceptional sensitive evidence | Expiry-aware backup and access audit |
| Ballot service | Campaign/Core separated service | Committee | Secret ballot/integrity | No identity joins; public verification |
| Pi 5/OptiPlex/general hardware | Record actual owner | Owner unless dedicated purchase | Mixed/dedicated as recorded | No percentage reimbursement of general overhead |
| Dedicated campaign hardware | Committee where practical | Committee | Campaign | Asset record, custody, wipe/transfer |
| AI/model providers | Dedicated campaign account/key where practical | Committee actual cost | Approved data classes only | Export/rotation/spend cap |
| Voice provider | Dedicated campaign credential | Committee actual cost | Agent response text; no caller raw audio by default | Rotation and usage record |
| Backup destinations | Committee or approved custodian | Committee actual cost | Encrypted restricted | Geographic separation and restore evidence |
| Monitoring and alerts | Approved account | Committee actual cost | Minimized operational | Export and incident retention |
Schedule F - Fixed implementation milestone register
| Milestone | Fixed payment | Included acceptance package |
|---|---|---|
| M0 - Baseline, governance, pricing, IP, and full requirements traceability | $4,000 | Schedules A-C complete; ADR and status register; no-retroactive boundary accepted |
| M1 - Sovereign infrastructure, storage, identity foundation, backup, and restore | $8,000 | Hardened deployment, SSD/UPS as applicable, Keycloak, private networks, encrypted backup, clean restore |
| M2 - Campaign Core authority, consent, roles, events, jobs, approvals, and finance boundaries | $9,000 | Complete typed authority slice, migrations, denial/replay/concurrency evidence |
| M3 - Hermes profiles, plugin, knowledge, memory, connectors, goals, outreach, and transparency | $9,000 | Isolated profiles, source-backed tools, connector fabric, goal/outreach flows, signed transparency slice |
| M4 - Public web, account, accessibility, deliberation, receipt, results, and audit interfaces | $8,000 | Complete browser journeys, accessibility evidence, no direct authoritative frontend writes |
| M5 - KYN Trust Core, claims, attestations, challenges, credentials, recovery, and Phase 2 pilot | $10,000 | Deterministic services, privacy boundary, seeded abuse/audit pilot, published redacted report |
| M6 - Verified polling, authorization/ballot separation, deterministic tally, receipts, and public verifier | $9,000 | Phase 3 poll, immutable manifest, no identity-ballot join, reproducible audit package |
| M7 - Expanded credentials, privacy interoperability, statewide hardening, crypto evaluation, and external-review readiness | $9,000 | Phase 4/5 readiness evidence, load/recovery/correlation tests, review packet and remediation record |
| M8 - Open-source release, final acceptance, migration/cutover, handoff, and 30-day stabilization | $6,000 | Pinned public release, runbooks, final acceptance record, transition materials, stabilization completion |
| Total fixed implementation fee | $72,000 | No additional fixed payment without prospective approval within the program ceiling |
A milestone may be subdivided in Schedule F only if the total fixed fee does not increase and each payment remains tied to independently useful accepted deliverables.
Schedule G - Public program allocation and transparency record
The Committee should publish, at an appropriate level of detail:
the $150,000 maximum technology program goal;
the related-party relationship;
the fixed implementation and operations ceilings;
cumulative contributions received for the Committee, subject to lawful privacy;
obligations, invoices, direct costs, payments, refunds, credits, and unspent reserves;
milestone status and acceptance evidence;
open-source releases and public audit artifacts;
material changes, incidents, external findings, stop decisions, and limitations; and
final disposition of unused technology-program funds.
Public reporting must not disclose donor information beyond legal/public filing requirements, KYN evidence, participant relationships, security-sensitive details, private campaign strategy, or ballot selections.
Reference basis
This draft is based on:
the AI for Wisconsin authoritative campaign repository and its system constitution, target architecture, data/event model, implementation plan, acceptance criteria, security/privacy/operations policy, Hermes integration specification, tools, public-input policy, and office transition runbook;
the July 25, 2026 Know Your Neighbor privacy-preserving civic identity and polling investigation;
the existing public campaign website, Hermes preview, Pi 5/OptiPlex infrastructure, and related repositories as documented at the baseline date;
Wisconsin Ethics Commission campaign-finance guidance and requested-advice process; and
public wage and vendor-pricing references used only to test broad price reasonableness, not as a formal appraisal.