Home › Use Cases › Assemble an estoppel certificate from the lease and prove every statement traces to it
Use caseUC0470
🧪 Use-case kit · runnable

Assemble an estoppel certificate from the lease and prove every statement traces to it

A small, forkable project that does one job end to end. Run once for real, and every figure on these pages captured from that run.

The business caseThe problem this solves

A lender or a buyer asks for an estoppel certificate, and before anybody can sign one somebody has to assemble the PACKAGE behind it: the lease clauses, the amendment schedule, the rent and deposit ledger postings, the notices, the governance records, and the file notes. Eight statements have to come out of it — the term, the base rent in force, the deposit held, the amendments of record, the renewal option and its exercise state, the absence of an uncured default, the assignment and sublease consents, and the operating-expense reconciliation — each either SUPPORTED by a named record on the package or UNSUPPORTED for one of seven stated reasons. Most of that is a column read. On 20 of the 64 packages in this corpus a FILE NOTE somewhere else in the package takes a printed record out of play — and on 35 more a note carries exactly the vocabulary of one and takes nothing out of play at all. Opening one estoppel package, reading five printed record blocks against the eight ESTP-2026 statements, testing each candidate record against the package's own declared register scope and lookback window, reading every file note to see whether it takes a record out of play AS AT the date the note carries, auditing the two interlocks against the certificate they name, and carrying the amendments, registers and parties the cited records pull in out with the answer.

Audience

The lease administration desk of a commercial property manager drafting an estoppel certificate for a lender or a buyer, and the counsel and officer whose review and signature the package has to evidence. The decision it supports is 'is this package ready to be reviewed and signed' — never whether the certificate may be issued, and never what the lease is worth. Every number on these pages came from one real run of this code, not from a vendor page.

The inputThe actual estoppel packages

The corpus is 64 estoppel packages, 0.12 MB (json 4 · jsonl 1 · md 2 · txt 64). No public corpus of estoppel packages exists, and one built from real leases would carry real parties, real rents and real defaults. Every package here is generated in process from one seed, so the key is DERIVED by the same rulebook the kit applies and the whole set rebuilds byte-identically. The mixture is the measurement: 20 packages a file note decides, 35 carrying a decoy note that reads exactly like one, 4 where the deciding note is dated AFTER the certificate date, 10 source traps, 5 lineage traps and 15 packages whose desk note asks in terms for the certificate to be issued, signed or waived.

The corpus

  • The 64 estoppel packagesgenerated from a fixed seed, so no real record, person or institution appears in it.
  • Where each came fromdata/SOURCES.md states where every byte came from AND what the generator costs the measurement. Every lease, property, party, register, record id and certificate id is invented, generated from SEED 20264700, and THERE ARE NO PEOPLE IN THIS CORPUS AT ALL — a party is a code and every file note speaks for the lease administration, records, transactions, counsel, asset management or lender desk. evals/check_labels.py sweeps all 64 packages for a person-shaped name, an honorific and an unattributed note on every run and reports 0. The best free-code floor is published there too: 44 of 64 whole-package, measured before any call was bought.

Swap this folder for your own material and the kit is pointed at your estoppel packages. That is the whole change — there is no database to migrate.

One estoppel package, as the model receives itEST-0001.txt · 1 of 64
ESTOPPEL CERTIFICATE PACKAGE  EST-0001
PACKAGE ASSEMBLED  2026-05-31   STANDARD  ESTP-2026

PROPERTY  PRP-4428   SUITE  SUITE-256
LEASE  LSE-26-0448   TENANT  TEN-3140
CERTIFICATE DATE  2026-05-26   REQUEST  REQ-7519   ADDRESSEE  ADR-2287
DECLARED SCOPE  REGISTERS LEASEVAULT, RENTLEDGER   LOOKBACK 365 DAYS FROM 2025-05-26

[1] LEASE CLAUSES
ID          DATED       TYPE             REGISTER     STATUS
CLS-70000   2024-04-20  TERM             LEASEVAULT   EXECUTED
CLS-70001   2024-04-20  RENEWAL-OPTION   LEASEVAULT   EXECUTED
CLS-70002   2024-04-20  USE              LEASEVAULT   EXECUTED

[2] AMENDMENTS
ID          EXECUTED    AFFECTS      REGISTER     EFFECTIVE   STATUS
AMD-30000   2024-12-15  BASE-RENT    LEASEVAULT   2024-12-30  EXECUTED
AMD-30001   2025-06-24  USE          LEASEVAULT   2025-07-09  EXECUTED

[3] LEDGER POSTINGS
ID          POSTED      KIND             REGISTER     PERIOD    STATUS
LDG-61000   2026-03-14  RENT-SCHEDULE    RENTLEDGER   2026-03   POSTED
LDG-61001   2024-04-22  DEPOSIT-HELD     RENTLEDGER   2024-04   POSTED
LDG-61002   2026-03-06  CAM-RECONCILE    RENTLEDGER   FY2025    POSTED
LDG-61500   2026-03-26  RENT-SCHEDULE    RENTLEDGER   2026-03   POSTED

[4] NOTICES
ID          SERVED      KIND             PARTY     SUBJECT       STATUS
NOT-88000   2025-09-15  DEFAULT          PTY-4462  LSE-26-0448   SERVED
NOT-88001   2025-10-05  CURE-CONFIRMED   PTY-4462  NOT-88000     SERVED

[5] CONSENTS, REVIEW AND SIGNATURE
ID          DATED       KIND             SUBJECT       ROLE               STATUS
CNS-44000   2025-10-30  CONSENT          LSE-26-0448   ASSIGNMENT         GRANTED
CRV-11000   2026-05-24  COUNSEL-REVIEW   EST-0001      COUNSEL            COMPLETE
SGN-22000   2026-05-25  SIGNATURE        EST-0001      OFFICER            SIGNED

Abridged — the file continues.

The outcomeWhat a good result looks like

One estoppel package in, one draft certificate out: the certificate id, the eight ESTP-2026 statement rows with the record ids that support each or the reason it does not, one DRAFT-COMPLETE or DRAFT-INCOMPLETE verdict, the two interlock rows — counsel review of THIS certificate and an officer's signature — a second INTERLOCKS-SATISFIED or INTERLOCK-BREACH verdict, and the three lineage lists the cited records drag out with them: amendments, registers, parties. 63 of 64 packages come back with all eight graded fields right once the free station has re-applied the rulebook, against 44 for the floor of record.

And when it cannot

And what it does when it cannot. 64 of 64 replies parsed, 0 stopped at the output ceiling and no call failed. The one package it gets wrong is named in the kit README with the sentence that decided it — EST-0031, where a file note rescinded a consent and the call read no withdrawal at all, so the station found the consent printed and GRANTED and returned DRAFT-COMPLETE against a DRAFT-INCOMPLETE key. A reply that cannot be parsed is counted WRONG and stays in the denominator; it is never dropped and never re-fired.

Where it fitsWhat did work

Every line below is a measured result from this kit's own runs, with the figure that supports it. The headline above is not softened by any of them.

  • The record changes in your lease files arrive as a STATUS column, not as a sentence — the printed-columns floor (b000-estoppel-package-columns)
    on the 44 packages this corpus decides from the columns alone, the free rule and the paid call are level at 44 of 44. Nothing is bought.
  • File notes decide, and they are written in ordinary prose — the scored run, with src/recheck.py behind it
    on the 20 packages a note decides, the free floor is 0 of 20 and the paid arm is 19. That gap is the entire case for this kit.
  • You want the amendments, registers and parties carried out with the answer — either floor
    the free floor is already 59 of 64 on the three lineage lists. Nobody should buy a call for them.
  • You need the interlock verdict — counsel review and an officer's signature — free code, and read the constant beside it
    one fixed answer reaches 55 of 64 on the interlock verdict, because 55 of the 64 packages are INTERLOCKS-SATISFIED. The paid arm's 64 of 64 is real but it is not what you are buying.
  • Untrusted text can reach the file notes block of a package — provenance on the notes block, before any of this
    the adversarial arm moved the withdrawal reading on 4 of 28 trials and no counter in this kit fired. The cap held 28 of 28; the reading is not defended.

At a glanceHow the whole thing runs

98%whole package rechecked pct
3,154 msp50, end to end
$3.88per 1,000 estoppel packages · the fast tier

Run once, for real, on 2026-09-14. Every figure on these pages was captured from that run — nothing is written from intent.

14 steps, grouped by the question that sends you to them rather than by build order. Each tile carries the one figure that step is about, and opens the page behind it.

Should you use this?What you bring, where it stops, and when not to use it

Before you commit an afternoon to this, these are the answers that decide it. Each one is rendered from the record it lives in — and links the page that holds it in full.

What do I have to bring?Replace data/corpus/*.txt with your own estoppel packages in the same shape — header, DECLARED SCOPE line, five printed record blocks, file notes — and data/packages.json with your own register, then edit data/policy.json so the eight statements, the seven reason codes, the per-statement ladders and the two interlocks are YOURS. ⚠︎ WHAT STOPS BEING TRUE THE MOMENT YOU DO. Corpus lens →
When is this the wrong choice?Avoid: Buying a call per package to re-read columns you already have in a database. That is the case against the best-fitting scenario (“The record changes in your lease files arrive as a STATUS column, not as a sentence”). 5 scenarios scored in all, each with its own. Eval lens →
Where does it stop working?A package with no DECLARED SCOPE line. The register-scope and lookback tests are 'inside the declared registers and the declared window'; with neither declared there is nothing to test against and the kit would be inventing a scope. 7 recorded failure modes, each from a run rather than a guess. Corpus lens →
What was never verified?NO SECOND SCORED RUN. One was fired, so the run-to-run spread on this corpus is unknown and no confidence interval is claimed anywhere on this page. 10 items this kit says it could not check. Eval lens →
Can I run this on a model I control?Yes — any OpenAI-compatible endpoint, including one on your own hardware. The shipped adapter takes its host from BASE_URL and its model from MODEL, so nothing in src/ changes. The published figures come from 1 model on the fast tier, one provider, one key. Prompt lens →
And if it fits — what do I stand up?6 artifacts with a stated home and a stated egress, and 3 decisions each with what you provision past its ceiling — plus what was not measured. That is the next page, not this one. step 14 — Run it in your environment →

Not asked of this kit — 2 questions: clone (a fresh clone of this kit runs with nothing fetched); judge (nothing here is graded by a model).

Last verified 2026-09-14 — r001-estoppel-package. Every figure on these pages was captured from that run.

Run itHow this reaches your data

Every result on this page was produced by pure code over checked-in files, with no API key — which is why you can read the numbers before anyone spends anything.

Run this on your own data

  • The pipeline, its eval harness and the runs behind every numberdeployed inside your environment, on your own model endpoints, against your own documents.
  • The corpus above is the shape, not the limitit is a folder swap, and there is no database to migrate.

Talk to us →

Checked before this shipped — A clean checkout with no key configured renders the whole board, runs the free floors live in the browser and replays every committed arm. pip install -r requirements.txt installs nothing — the kit is standard library only. The only thing a key buys is the ASK THE MODEL button and a new scored run; without one the button is disabled and says so.

A living map of modern AI — kept current every morning