# Gap Analysis — Concordia vs. Pactum and Nibble

Analysis date: **2026-04-23**

Scope: Phase 179 Concordia task `179.1.1.4`.

This analysis measures Phase 179 Concordia against Pactum and Nibble, the
two most mature autonomous-negotiation commercial systems in the audit. It
complements the Mediator.ai gap analysis at
[`gap-analysis-mediator-ai.md`](./gap-analysis-mediator-ai.md). Where
Mediator.ai defines the consumer cooperative-negotiation frontier, Pactum
and Nibble define the **enterprise procurement and commerce-negotiation
frontier** — the category Concordia's Maat (§179.7.1), Aglaea / Freya
(§179.7.5), and agent-to-agent (§179.7.6) integrations must surpass.

The seven gap axes required by `179.1.1.4`:

1. Procurement and commerce negotiation workflows
2. ERP and marketplace integration
3. Supplier audit trails
4. Objective savings metrics
5. Supplier satisfaction metrics
6. Campaign management
7. Guardrailed autonomous execution

For each axis: the Pactum baseline, the Nibble baseline, the Concordia
requirement, the gap, the Phase 179 task pointers that close it, and an
evidence note. The audit source material lives in
[`mediation-negotiation-2026.md`](./mediation-negotiation-2026.md) §8 and
§9; the tagged sources are in [`source-matrix.md`](./source-matrix.md) §B.

## 0. Baseline summaries

### Pactum

- **Category:** Enterprise procurement negotiation (agentic AI for supplier
  negotiations). Global 2000, Fortune 500 buyers.
- **Autonomy:** Variable and configurable. "Autonomously or with buyer
  approval" within guardrails set by procurement policy. Highest effective
  autonomy in the audit cohort.
- **Architecture (public):** AI agents embedded in enterprise systems via
  standard APIs; integrate with ERP / procurement / CMS; chat-style
  negotiation with suppliers; policy-bounded decisioning. Specific LLMs
  and algorithms not disclosed.
- **Compliance:** **SOC 2 Type II certified**. Full negotiation audit
  trails. Trust portal at trust.pactum.com.
- **Deployment:** Claims 2–4 week deployment. Named customers include
  Walmart, Honeywell, Bristol Myers Squibb, Veritiv, Suez, Linde, Novartis,
  Tetra Pak, Mediclinic, Otto, Global Industrial, Vallen.
- **Outcomes (third-party verified for Walmart, Sourcing Journal):** 3%
  average savings, +35 days payment terms. 60+ Global 2000 enterprises.
  $54M Series C in June 2025 led by Insight Partners. 489% YoY spend
  growth handled, 2.5× ARR.
- **Scope:** Bilateral negotiations run massively in parallel. Not
  multi-party. Category-specific to procurement spend (price, payment
  terms, rebates, service levels).

### Nibble

- **Category:** Commerce- and procurement-side negotiation chatbot.
  Originally DTC e-commerce make-an-offer; expanded into B2B procurement.
- **Autonomy:** High. Handles mass renegotiations autonomously via
  self-serve portal or API; negotiates with hundreds of suppliers or
  thousands of shoppers in parallel.
- **Architecture (public):** Agentic AI with custom LLM guardrails where
  "pricing functions" are kept "secure, controlled and never seen by any
  LLM" — the LLM handles language, a deterministic pricing engine holds
  the numbers.
- **Compliance:** **ISO 27001 certified.** "Your data is your data"; data
  not used to train other implementations.
- **Deployment:** Plugins for Shopify, Magento, Adobe Commerce, Coupa, SAP
  Ariba, and CRMs.
- **Outcomes (self-reported):** 350+ organizations; ~30,000 negotiations
  per month; 2M+ cumulative automated negotiations; deal range $5 to six
  figures.
- **Scope:** Bilateral per conversation, massive parallelism. Buy-side and
  sell-side.

---

## 1. Procurement and commerce negotiation workflows

**Pactum baseline.** Deep bilateral procurement workflows for supplier
pricing, payment terms, rebates, service levels, joint business plans,
capital allocation, shared services, hiring offers, board resolutions, and
cross-company resource conflicts (per their procurement-agents page).
Pre-sourcing and post-sourcing flows are first-class; Pactum specifically
targets "mid-tier and tail spend" where bilateral human negotiation is
uneconomic.

**Nibble baseline.** DTC make-an-offer flows (shopper → merchant), mass
supplier renegotiation (merchant → many suppliers at once), post-sale
discount / buy-back flows. Focused on price and payment terms; contract
harmonization on the procurement side.

**Concordia requirement.** Integrate with `@maat/strategy`, `@maat/finance`,
`@maat/supply-chain`, and `@maat/agents` for supplier pricing, payment
terms, rebates, service levels, joint business plans, capital allocation,
shared services, hiring offers, board resolutions, cross-company resource
conflicts (`179.7.1.1`). Add working-capital optimization: DPO extension,
early payment discounts, volume commitments, quality guarantees, warranty
terms, supplier relationship scoring (`179.7.1.3`). Add Pactum-class
procurement agents for Asase, Freya, Cybele, Brigid, Saraswati, Aje, and
Maat portfolio companies (`179.7.1.2`). Add returns, custom-order
disputes, fit/alteration compromises, pricing offers, resale authenticity,
creator collabs, and luxury-service recovery (`179.7.5.1`).

**The gap.** Concordia must **match** Pactum on the procurement bilateral
workflows and **surpass** it on (a) multi-party supplier cohort
negotiations (where Pactum runs parallel bilaterals, Concordia can model
coalition stability and Shapley attribution for joint volume commitments),
(b) non-price terms that Pactum does not treat as first-class (audit
rights, data-sharing, sustainability clauses, originality / IP provenance
when applicable), and (c) cross-domain workflows — Concordia's procurement
work inherits the same bargaining substrate used in Themis governance and
Kuanyin restorative flows.

**How Concordia closes it.**

- `179.7.1.1`–`179.7.1.5` — full Maat / portfolio procurement map.
- `179.4.2.4` — CP-SAT / MILP for discrete procurement constraints
  (schedules, budgets, ownership percentages, milestones, roster
  assignments, routing, shipment terms, resource allocation).
- `179.4.2.7` — coalition stability for supplier-cohort deals.
- `179.2.3.2` — agreement DSL covers money, equity, royalties, deadlines,
  deliverables, service levels, licensing, exclusivity, territory, data
  rights, warranty, confidentiality — the full procurement term surface.

**Evidence note.** Pactum's Walmart-reported 3% savings + 35-day DPO
extension is the strongest verifiable procurement baseline in the audit
(Sourcing Journal, strength B). Concordia's procurement agents have a
concrete outcome target to beat in `179.8.2.3`.

## 2. ERP and marketplace integration

**Pactum baseline.** "Embedded in enterprise systems via standard APIs,"
integrates with ERP / procurement / CMS. 2–4 week deployment. Specific
integrations not publicly enumerated beyond the enterprise-grade posture.

**Nibble baseline.** Explicit plugin catalog: Shopify App Store, Magento,
Adobe Commerce, Coupa, SAP Ariba, and CRM connectors. DTC plugins are
public; B2B plugins are enterprise-sales-gated.

**Concordia requirement.** OpenAPI endpoints at
`libs/openapi/src/specs/concordia/concordia-api.yaml` (`179.2.2.1`);
streaming RPCs under `libs/proto/src/concordia/` for live session
transcription, real-time co-mediator suggestions, offer/counter exchange,
search-progress updates (`179.2.2.2`); domain events (`179.2.2.3`);
tenant and domain configuration with legal disclaimers, eligible use
cases, model routing, review thresholds, data residency, execution
adapters, retention policy (`179.6.3.5`). App Router surface at
`/studio/concordia-workbench` (`179.2.4.4`).

**The gap.** Pactum and Nibble are integrated with a defined set of third-
party systems; Concordia is integrated with its own ecosystem first. To
compete in procurement specifically, Concordia must publish a
Pactum-equivalent ERP integration surface (SAP, Oracle, Coupa, Ariba,
NetSuite) and a Nibble-equivalent marketplace plugin surface (Shopify,
Magento, Adobe Commerce) so Maat and Aglaea / Freya customers can adopt
Concordia without ripping out existing systems. These integrations are
not explicitly called out in current Phase 179; they should be tracked
as deferred work under `179.7.1.*` and `179.7.5.*` adapters.

**How Concordia closes it.**

- `179.2.2.1`–`179.2.2.4` — contracts, OpenAPI, proto, events, codegen.
- `179.6.3.1`–`179.6.3.5` — orchestrator with event bus, observability,
  tenant config.
- `179.7.1.1` (Maat) — Coupa / SAP Ariba / Oracle / NetSuite adapters
  belong here; add as sub-items if not already covered.
- `179.7.5.1` (Aglaea / Freya) — Shopify / Magento / Adobe Commerce
  adapters belong here; add as sub-items if not already covered.

**Concordia follow-up:** Phase B or Phase C should spawn explicit
ERP and marketplace adapter tasks under `179.7.1.2` and `179.7.5.1`
respectively. Track in a follow-up refinement of the phase doc if the
current task list does not already enumerate them. (This document flags
the need; it does not modify the TODO list without authorization from a
higher-level task.)

**Evidence note.** Nibble's Shopify / Magento / Adobe Commerce / Coupa /
SAP Ariba plugin presence is the reference. Pactum's specific ERP list
is enterprise-gated and could not be confirmed in the audit.

## 3. Supplier audit trails

**Pactum baseline.** "Full negotiation audit trails" claimed; SOC 2 Type
II certified. Audit trail format and retention specifics not publicly
disclosed but implied by the compliance posture.

**Nibble baseline.** ISO 27001 certified. Privacy posture documented.
Audit-trail specifics not disclosed; data-isolation posture emphasized.

**Concordia requirement.** Audit retention, privilege / confidentiality
flags, data residency, deletion, legal hold, export controls per
use-case class (`179.1.3.5`). Audit events
`concordia.search.completed`, `concordia.draft.reviewed`,
`concordia.settlement.accepted`, `concordia.execution.completed`,
`concordia.escalation.required` (`179.2.2.3`).
`GET /concordia/audit/{id}` endpoint (`179.2.2.1`). Observability per
case, scoring cost, model latency, candidate diversity, preference
uncertainty, agreement rate, escalation rate, privacy-gate failures
(`179.6.3.4`). Evidence chain-of-custody (`179.5.4.3`). Agreements
reproducible through model and optimizer version pinning (`179.5.3.3`).

**The gap.** Concordia's audit posture is more granular than Pactum's
public claim and is designed to serve *legal*, *governance*, and
*compliance* consumers in addition to the procurement officer.
Concordia's audit events are addressable, queryable, and reviewable;
Pactum's are a compliance artifact visible to enterprise auditors on
request. Concordia's per-clause provenance (`179.2.3.3`) is a posture
neither vendor matches publicly.

**How Concordia closes it.**

- `179.1.3.5`, `179.5.3.3`, `179.5.4.3`, `179.6.3.4` — audit stack.
- `179.2.2.3` — event surface.
- `179.2.3.3` — clause-level provenance.
- `179.10.1` (`pnpm contracts:check`) and `179.10.9` (Nx graph coverage)
  — gate that audit schemas cannot drift.

**Evidence note.** Pactum SOC 2 Type II is the enterprise compliance
floor (strength B); Concordia's audit design is broader in scope but
must actually deliver the certifications to be credible at enterprise
procurement sales.

## 4. Objective savings metrics

**Pactum baseline.** Walmart case: 3% average savings + 35-day payment
term extension — the single most verifiable procurement-AI outcome
metric in the audit (Sourcing Journal, strength B). Pactum's marketing
implies comparable numbers across its 60+ Global 2000 customers but
does not publish per-customer breakdowns.

**Nibble baseline.** 350+ organizations, 30k negotiations / month,
2M+ cumulative negotiations, deal range $5 to six figures. Savings per
deal not broken out publicly.

**Concordia requirement.** Track domain metrics: procurement savings,
DPO change, supplier satisfaction, moderation recurrence, DAO proposal
pass rate, creative delivery acceptance, marketplace refund leakage,
settlement execution completion (`179.8.2.3`). Benchmark procurement
outcomes against manual historical negotiations: savings, cycle time,
supplier satisfaction, dispute rate, realized value (`179.7.1.5`).

**The gap.** Concordia must publish per-deployment outcome metrics in
the same coinage Pactum uses (savings %, DPO change, cycle time) or
Concordia procurement will not be taken seriously at enterprise sales
cycles. Concordia's benchmark gate (`179.10.6`) requires improvement
over baseline LLM mediator, simple Nash GA, static templates, and
human-authored seed-offer-only workflows on at least six domain
suites — this is necessary but not sufficient; procurement pilots
specifically need the Pactum-coinage outcome numbers.

**How Concordia closes it.**

- `179.7.1.5` — procurement benchmark against manual historical.
- `179.8.2.1`–`179.8.2.5` — full outcome metric stack (agreement rate,
  Pareto efficiency, Nash product, subjective value, domain metrics,
  cost, safety).
- `179.8.1.1` — synthetic procurement benchmark suite.
- `179.10.8` — pilot deployments show measurable value.

**Evidence note.** Pactum's 3% / +35-day Walmart number is a
well-sourced third-party metric (Sourcing Journal). Concordia's
procurement pilots should aim to publish equivalent numbers with
equivalent third-party or audit validation, not self-reported.

## 5. Supplier satisfaction metrics

**Pactum baseline.** Referenced in Pactum's marketing as a success
metric alongside savings and cycle time; specific supplier NPS /
satisfaction figures not publicly disclosed. The value proposition to
suppliers is "24/7/365" availability and predictable behavior, framed
as *better for suppliers* than random-access human buyers.

**Nibble baseline.** No publicly disclosed supplier-satisfaction data.
Commerce-side shopper satisfaction is implicit in the fact of
completed deals but not broken out.

**Concordia requirement.** Track subjective value: perceived fairness,
dignity, procedural transparency, relationship preservation, voice,
control, willingness to use again (`179.8.2.2`). Track restorative
outcomes: recurrence, participant sense of fairness, safety incidents,
completion of agreed obligations, community health (`179.7.3.5`).
Benchmark procurement outcomes including supplier satisfaction
(`179.7.1.5`).

**The gap.** Concordia's subjective-value measurement is first-class
and ported across *every* domain, not just procurement. This is a
genuine lead over Pactum, whose satisfaction framing is procurement-
specific and largely not publicly validated. The gap to close is
operational: run the subjective-value instrument on real pilots and
publish results.

**How Concordia closes it.**

- `179.8.2.2` — subjective-value instrument design and execution.
- `179.7.1.5` — procurement outcome benchmark including satisfaction.
- `179.7.3.5` — restorative outcome measurement.
- `179.10.8` — pilot success criteria include subjective value.

**Evidence note.** Peer-reviewed ProMediate (arXiv 2026) measures
consensus change, intervention timing, effectiveness, and
socio-cognitive intelligence — adjacent to Concordia's subjective-value
instrument and available as academic grounding. Pactum's supplier
satisfaction claims are marketing; Concordia must instrument and
publish.

## 6. Campaign management

**Pactum baseline.** Procurement teams configure policy, agents execute
campaigns of negotiations across supplier cohorts. Campaign lifecycle
(creation, targeting, policy attachment, monitoring, stopping) is a
product primitive; specifics of the campaign UI and lifecycle are
enterprise-gated.

**Nibble baseline.** Mass renegotiation is a headline capability —
"negotiate with 100s of suppliers in minutes." Campaign targeting,
policy, and self-serve portal are part of the product. Plugin-based
deployment means campaign management is partly inherited from the host
system (Coupa, Ariba).

**Concordia requirement.** Organization mode for procurement and
governance: settlement authority, approval chain, budget constraints,
policy bundles, signatory status, execution integration
(`179.6.1.4`). Executive approval gates for thresholds by value,
supplier criticality, jurisdiction, sanctions / KYC risk, reputation
impact (`179.7.1.4`). Background workers for intake summarization,
preference comparison batches, search runs, candidate validation,
legal / policy template matching, settlement drafting (`179.6.3.2`).
Tenant and domain configuration (`179.6.3.5`).

**The gap.** Campaign management is implied by Concordia's
organization mode and orchestrator design, but the Phase 179 task list
does not explicitly name a "campaign" primitive the way Pactum and
Nibble do. Concordia's language is "case," which fits legal and
governance framing but under-represents the procurement reality where
a single policy configuration spawns hundreds of concurrent supplier
negotiations. A follow-up refinement should add a campaign construct on
top of `ConcordiaCase` — not to replace the case primitive but to group
cases under a shared policy, approval chain, budget envelope, and
rollup metrics.

**How Concordia closes it.**

- `179.6.1.4` — organization mode (campaigns belong here as a
  sub-capability).
- `179.6.3.2` — orchestrator background workers handle campaign
  concurrency.
- `179.6.3.4` — observability rolls up campaign-level metrics.
- `179.7.1.4` — executive approval gates work at the campaign level.
- Concordia follow-up: add an explicit `ConcordiaCampaign` primitive
  under `179.2.1.1` or as an extension under `179.2.1.4` during Phase B;
  track as a refinement task when this TODO is revisited.

**Evidence note.** Pactum's explicit "mid-tier and tail spend" framing
and Nibble's "30,000 negotiations / month" are both campaign-level
throughput claims. A Concordia campaign primitive is the right way to
represent this without conflating it with the legal / governance case
primitive.

## 7. Guardrailed autonomous execution

**Pactum baseline.** "Autonomously or with buyer approval" within
guardrails set by procurement policy. Configurable autonomy is the
core differentiator. SOC 2 Type II certification provides the
compliance underpinning.

**Nibble baseline.** High autonomy inside merchant-configured policy
boundaries. LLM never sees pricing functions (claim): language handled
by LLM, numeric offers by a deterministic engine. ISO 27001 is the
compliance underpinning.

**Concordia requirement.** Policy-constrained autonomous acceptance
where agents can accept only within explicit authority bounds and must
log all offers (`179.7.6.3`). Adversarial negotiation tests for prompt
injection, hidden-tool access, budget escalation, side-channel data
leakage, collusive agent behavior (`179.7.6.4`). Economic-value scoring
(`179.7.6.5`). Authority fields on contracts: `canNegotiate`,
`canAccept`, `canBindOrganization`, `requiresHumanApproval`,
`requiresCounselReview`, `requiresGuardianOrRepresentative`,
`settlementLimit` (`179.2.1.3`). Identity / authority / conflict-of-
interest / RBAC / ABAC (`179.2.5.*`). Kill-switch and feature-flag
controls for mediation model routing, autonomous acceptance,
smart-contract execution, search kernels, domain adapters
(`179.5.5.3`). Financial and procurement controls: sanctions / KYC,
payment rails, invoice reconciliation, tax treatment, currency exposure,
approval thresholds, segregation of duties (`179.5.5.4`). Reviewer
capacity controls, queue SLA, dual-control for high-risk cases,
calibration review, audit sampling, escalation when no qualified
reviewer is available; blocked launch status for unstaffed review
gates (`179.5.5.1`).

**The gap.** Concordia's guardrailed-autonomy posture is **architecturally
deeper** than Pactum or Nibble's public posture — authority fields are
typed contracts, kill switches are first-class, adversarial tests are a
specified deliverable. The gap to close is operational: Concordia must
actually ship the identity, RBAC / ABAC, conflict-of-interest, and
financial-controls stack before any autonomous execution path is
enabled. Phase 179.9.1.6 and §179.9.2.6 already gate on this.

Nibble's specific claim that "pricing functions are never seen by any
LLM" is a good design pattern Concordia should adopt in procurement
adapters: the LLM handles language and structure, a deterministic
engine holds the numbers and enforces authority bounds. This is not
currently a named Phase 179 task but fits naturally under
`179.4.1.3`'s sandboxed-DSL clause mutators and `179.7.1.4`'s executive
approval gates.

**How Concordia closes it.**

- `179.2.1.3` — typed authority fields.
- `179.2.5.1`–`179.2.5.5` — identity, authority, RBAC / ABAC, conflict
  of interest, rate limits / abuse throttles.
- `179.5.5.1`–`179.5.5.4` — reviewer capacity, settlement lifecycle,
  kill switches, financial / procurement controls.
- `179.7.6.3`–`179.7.6.5` — policy-constrained autonomous acceptance,
  adversarial tests, economic-value scoring.
- `179.9.1.6` and `179.9.2.6` — phase-gating on identity / authority /
  autonomous-execution controls.
- `179.10.10` — authorization-automation coverage gate.

**Evidence note.** Pactum SOC 2 Type II and Nibble ISO 27001 are the
enterprise-compliance reference bar (strength B each). Concordia's
architecturally deeper posture is meaningful only if it ships with
equivalent or better certifications before a Phase C procurement
pilot. The pilot-readiness section in `179.9.3.1` must include a
certification track.

---

## Summary table

| Axis | Pactum baseline | Nibble baseline | Concordia delta | Task pointers |
| --- | --- | --- | --- | --- |
| 1. Workflows | deep bilateral procurement; 2–4 wk deploy | DTC + B2B mass renegotiation | match + coalition + non-price + cross-domain | 179.7.1.*, 179.7.5.1, 179.4.2.4, 179.4.2.7, 179.2.3.2 |
| 2. ERP / marketplace | ERP + CMS standard APIs | Shopify / Magento / Coupa / Ariba plugins | publish Pactum-equivalent ERP + Nibble-equivalent plugin surface | 179.2.2.*, 179.6.3.*, 179.7.1.1, 179.7.5.1 (add adapters) |
| 3. Audit trails | SOC 2 Type II + claimed full logs | ISO 27001 + data-isolation posture | per-event, per-clause provenance, reviewer-review linkage | 179.1.3.5, 179.2.2.3, 179.2.3.3, 179.5.3.3, 179.5.4.3, 179.6.3.4, 179.10.9 |
| 4. Savings metrics | Walmart: 3% savings + 35d DPO (Sourcing Journal) | Volume, not savings % | publish per-pilot savings / cycle / satisfaction | 179.7.1.5, 179.8.2.*, 179.10.6, 179.10.8 |
| 5. Supplier satisfaction | "24/7/365 availability" framing | not disclosed | first-class subjective-value instrument across domains | 179.7.1.5, 179.7.3.5, 179.8.2.2, 179.10.8 |
| 6. Campaign management | core primitive (enterprise-gated) | mass renegotiation + plugin host | add `ConcordiaCampaign` primitive on top of case model | 179.6.1.4, 179.6.3.2/4, 179.7.1.4 (+ follow-up) |
| 7. Guardrailed autonomy | configurable autonomy + SOC 2 Type II | high autonomy, numeric-never-in-LLM + ISO 27001 | deeper typed authority + kill switches + adversarial tests + certifications | 179.2.1.3, 179.2.5.*, 179.5.5.*, 179.7.6.3–5, 179.9.*.6, 179.10.10 |

---

## Strategic read

Pactum and Nibble collectively set four bars Concordia must clear for
procurement and commerce credibility:

1. **Named outcome metrics.** Procurement buyers expect savings-%,
   DPO-change, cycle-time numbers. Concordia's Phase C procurement
   pilots (§179.9.3.1) must publish these, ideally with third-party
   validation.
2. **ERP / marketplace adapter catalog.** Concordia needs a published
   adapter matrix (SAP, Oracle, Coupa, Ariba, NetSuite, Shopify,
   Magento, Adobe Commerce) with integration-sample repos — Nibble's
   plugin presence is the reference model.
3. **Enterprise certifications.** SOC 2 Type II and ISO 27001 are table
   stakes in this category. Phase C pilot-readiness must include a
   certification track running in parallel with the engineering track.
4. **Configurable autonomy.** Not just "the system can act"; the system
   can be dialed from advisory to fully autonomous per use case, per
   tenant, per policy bundle, with reviewer capacity and kill switches
   intact. Concordia's typed authority fields and §179.5.5 kill
   switches already architect for this; the delivery gap is integrating
   autonomy dials into the workbench and tenant configuration.

Concordia's durable advantages over Pactum and Nibble:

- **Multi-party coalition bargaining** (`179.4.2.7`) — Pactum runs
  parallel bilaterals; Concordia can model joint commitments.
- **Cross-domain substrate** — the same bargaining engine serves Maat
  procurement, Themis governance, Kuanyin restorative, Iris personal,
  Yemaya creative, and agent-to-agent; Pactum / Nibble are
  category-bound.
- **Uncertainty-aware preference inference and stability tests**
  (`179.3.*`) — Pactum / Nibble do not disclose this capability.
- **Agreement DSL with static validation** (`179.2.3.*`) — Pactum /
  Nibble negotiate numbers within rails; Concordia can reason about
  clause-level constraints, impossibility, and contradiction.
- **Formal privacy isolation** (`179.5.1.*`) — Pactum / Nibble have
  compliance certifications but do not disclose physically isolated
  per-party prompt contexts.
- **Governance appeals + restorative integration** — Concordia's
  Themis / Kuanyin integrations are without peer.

## Follow-ups to track

These are gaps identified by this analysis that are not explicitly
enumerated as Phase 179 tasks today. They should be raised in a future
refinement of Phase 179.7 or Phase 179.9 planning:

- Explicit ERP adapter tasks under `179.7.1.*` (SAP, Oracle, Coupa,
  Ariba, NetSuite).
- Explicit marketplace adapter tasks under `179.7.5.*` (Shopify,
  Magento, Adobe Commerce).
- `ConcordiaCampaign` primitive grouping `ConcordiaCase` records under
  shared policy / approval / budget envelope.
- Certification track (SOC 2 Type II, ISO 27001, and — where
  applicable — SOC 2 HIPAA / GDPR DPIA artifacts) for Phase C pilots.
- LLM-never-sees-numbers pattern for procurement adapters, borrowed
  from Nibble's public architecture posture.

These follow-ups do not modify the current TODO list — they are flagged
here so the next Phase 179.7 / 179.9 refinement pass can incorporate
them under their proper parent tasks.

## Caveats

- Pactum's specific ERP integration list, internal algorithms, and
  non-Walmart outcome numbers are enterprise-gated. This analysis uses
  the strongest publicly available material. The refresh gate in
  `179.1.1.6` should re-run before Concordia procurement pilot launch.
- Nibble's "LLM never sees pricing" claim is a marketing statement
  (strength C). Concordia can adopt the pattern as a design principle
  but should verify Nibble's implementation detail via third-party
  review if a tight competitive comparison is needed.
- Both vendors operate in bilateral modes. Concordia's coalition
  advantage is a design lead; the operational proof is in §179.8
  benchmarks and §179.9 pilots.
