Meet Keepsake
A fictional product story that shows why Avendo exists, without pretending the example is a real customer result.
Before Avendo
A small app team has built Keepsake, an iPhone app that repairs scratches, restores faded color, and sharpens old family photos. The product works. The marketing does not.
One ad talks about AI. Another lists every feature. The store page promises nostalgia. Approvals happen in chat, results live in a dashboard, and the next campaign begins with somebody asking, “What did we learn last time?”
Avendo's job is to turn what is true about a product into a campaign decision, then preserve what the result taught the team.Begin with product truth
Chapter 1 — Understand the product
Keepsake begins with evidence, not a blank prompt.
The team pastes its public App Store URL. Avendo captures the page, records when it was observed, and separates source facts from marketing claims that still need a person to approve.
Product Truth gives the team one factual boundary. AI may organize and propose, but it cannot silently turn an inference into an approved promise.
Chapter 2 — Find the opening
The product is understood. Now the team needs to know which problem is worth testing.
Discover connects the product with current, source-linked signals. In this example, public searches and reviews repeatedly mention repairing scratched photos, preserving grandparents' pictures, and seeing a convincing before-and-after.
This is evidence of language and interest—not proof of revenue or conversion.
This is a testable hypothesis, not a guaranteed winning concept.
The question is no longer “What ad should we make?” It is “Will visible proof, framed around a family memory, produce more qualified engagement?”
Chapter 3 — Choose what to say
Avendo turns evidence into distinct campaign directions that a human can inspect before deciding.
The team defines an observable goal: increase completed first restorations among new visitors. Avendo proposes several directions, each with a different mechanism, opening hook, audience, offer, cited evidence, and claim risk.
The photo they remember
A memory-led before-and-after that makes the emotional value visible.
Watch the damage disappear
A direct product workflow showing repair steps without adding unsupported claims.
Save one family archive
A repeatable challenge built around restoring a small set of meaningful photos.
The team opens the review packet for the first direction. It checks the intended audience, offer framing, hook, script, evidence used, claim risk, and concept distinctness. Approval makes the direction available in Studio; it does not render an asset, publish a campaign, or spend money.
A direction is now a reviewable decision with provenance—not a mysterious AI answer or a line lost in a chat thread.
Chapter 4 — Make and approve the work
Studio carries the approved reasoning into production so the creative does not drift away from the evidence.
The chosen hook, claim, script, CTA, and source evidence arrive together. The team adds a rights-cleared photo, builds a vertical before-and-after, checks captions and safe areas, and reviews the final render.
Create from the approved direction
The asset begins with the chosen hypothesis and cited claim instead of a new blank brief.
Review the rendered work
A person checks legibility, pacing, rights, claims, destination, and channel fit.
Prepare the launch
Avendo creates an export package or uses an explicitly connected provider. Nothing publishes invisibly.
The team can trace the finished asset back to the decision and evidence that produced it. Approval records responsibility instead of replacing it.
Chapter 5 — Launch, measure, and learn
A campaign becomes valuable twice: first when it runs, and again when its outcome improves the next decision.
Keepsake records the experiment version, which variant a visitor saw, and the agreed success event: first_restoration_completed. Avendo waits for sufficient evidence before turning an outcome into an accepted learning.
The finding stays tied to its market, audience, creative, and measurement window.
A weak or inconclusive result is not rewritten as success.
That connected chain is Avendo. Not another ad generator. Not another dashboard. A campaign operating system that keeps product truth, human judgment, execution, and learning together.Use the workflow yourself
Start here
Avendo turns product evidence into campaign work that stays reviewable from first capture to launch.
Add a real product
Paste a public product, App Store, or Google Play URL. Avendo captures the page and stores the source.
Review Product Truth
Inspect facts, proposed claims, evidence quotes, source status, and confidence; approve supportable claims before campaign use.
Create a campaign
Set the outcome you want. Avendo drafts distinct directions from the available evidence.
Approve the right direction
A qualified workspace member approves, rejects, or requests changes before production continues.
Create, export, and learn
Build the creative, approve the render, create a launch package, and send authenticated outcomes back through the event API.
The Avendo workflow
Every surface contributes to one controlled learning loop.
Avendo separates observation from inference. Captured sources and measured outcomes are evidence. Model-generated facts, claims, forecasts, and directions are derived objects with their own status. Nothing becomes approved simply because AI generated it.
Activation and first proof
Activation is a precise product milestone—not a login, page view, or generated draft.
The activation definition
- A real product finishes analysis
- A person reviews one product claim
- A person approves one campaign direction
- The approved direction is opened in Studio
Why these four steps
Together they prove that Avendo moved a team from source evidence to a production-ready decision while preserving human judgment. The dashboard reads each milestone from stored workspace records and points to the first incomplete step.
The verified proof gate
- A durable launch or export receipt
- At least one authenticated success outcome
- A learning that a person explicitly promoted
What Avendo withholds
Until all three checks exist, Avendo labels case-study proof as withheld. It does not convert a model forecast, generated direction, click, or unreviewed learning into a customer result.
Founding activation cohort
Teams with a real analyzed product can request hands-on onboarding from the dashboard. Avendo records the launch goal, time window, and area where support is most useful. A request is not automatic acceptance; the first cohort is capped at ten organizations so each can be helped through a real launch.
Product Truth
Product Truth is the evidence layer that campaigns use as their factual boundary.
What is stored
- Captured source URL, title, snapshot, screenshot, and capture time
- Extracted facts with confidence and supporting evidence
- Proposed claims with risk and review status
- Version history for every completed evidence run
How to review it
- Confirm the source is the intended product and market
- Check that evidence quotes support the exact statement
- Treat proposed claims as unapproved until reviewed
- Refresh evidence when the product page changes materially
Discover
Discover observes store, search, review, competitor, and creative signals before a campaign is committed.
Connect the product
Choose the app or product that should own the observed signals.
Choose markets
Track the storefronts and locales that matter to the actual launch.
Read provenance
Observed, derived, estimated, and inferred data are labeled differently.
Turn signals into tests
Use strong patterns as hypotheses, not as guaranteed outcomes.
Radar
Radar turns source-linked creative references into reviewable patterns, product-fit decisions, and controlled research briefs.
Save references
Import public HTTPS URLs. Radar records canonical metadata, source policy, rights class, provenance, and capture history without copying third-party media.
Classify what is visible
Label the hook, format, proof type, CTA, audience, and your research notes. Each edit creates a new annotation version.
Group a pattern
Select at least two references and describe the repeated execution and its possible mechanism. The pattern remains pending until a human accepts it.
Evaluate product fit
An accepted pattern is compared with Product Truth facts and approved claims. The fit score cites the exact supporting evidence.
Create a research brief
Adapt the mechanism to your product as one controlled variable. Keep the audience, offer, placement, budget, and measurement window stable.
What Radar can say
- A public creative or landing page was observed
- Several references share an operator-reviewed pattern
- A pattern overlaps with cited Product Truth
- A controlled test is worth considering
What Radar cannot say
- Public attention caused conversions
- A competitor's spend, ROAS, or targeting is known
- A source is licensed beyond the recorded rights class
- A pattern will work for your product before testing
Model and product-value evidence
Automated Creative DNA remains reviewable rather than self-validating. In Radar → Source & Rights, Avendo lists eligible and excluded references, lets an authorized reviewer freeze coverage, hook precision/recall, and creative-family false-merge thresholds for exact model and taxonomy versions, then produces a SHA-256 identified evaluation package. Only rights-attested customer-owned or licensed references paired with a human correction and automated prediction can enter the package. Failed packages remain visible audit history; unit-test fixtures are rejected as release evidence.
Radar measures first capture-to-classification time only from server timestamps and only for a user's first classification. Research-time reduction is reported only for completed sprints paired with an observed, same-user, same-product, same-question manual baseline. The Source & Rights view remains insufficient evidence until ten real sessions exist for the relevant metric.
Source and rights controls
The Source & Rights view shows the current policy version for every supported source. Initial policies allow metadata references and block third-party media storage and commercial-metric inference. They remain marked pending legal review until the relevant platform and legal owners approve them.
Install Radar Capture
Radar Capture is available as a reviewed Manifest V3 unpacked extension while Chrome Web Store publication is pending. Download version 1.1.0, unzip it, open chrome://extensions, enable Developer mode, choose Load unpacked, and select the extracted folder. Version 1.1 adds source-specific golden adapters, credential-like URL blocking, selected-text redaction, and a complete field preview.
Open a public HTTPS page
Optionally select a short piece of visible text that explains why the reference matters.
Preview the allowlisted fields
The extension shows the URL, page title, publisher, selection, media policy, and credential boundary before continuing.
Confirm inside Avendo
The payload travels in the URL fragment, which is removed immediately. Choose the product, collection, distribution, and notes in your signed-in workspace.
Review in Radar
Avendo verifies the source server-side, records the policy and capture audit, and avoids duplicates by canonical URL.
Current implementation boundary
The current release supports public URL import, explicit extension capture, reference collections, competitors and scheduled watchlists, landing-page change evidence, source-health alerts, cohort-aware scoring, reviewed Creative DNA, rights-attested media analysis, controlled research briefs, approval-locked Radar-to-Studio handoffs, deterministic render QA, idempotent export packages, versioned first-party outcome learning, tenant-scoped first-party connector infrastructure, and scheduled retention maintenance. Public third-party media remains metadata-only.
Customer-owned connections
App Store Connect and Google Play credentials are supplied by the workspace, encrypted with AES-GCM in private R2 storage, and decrypted only inside the authorized sync or publishing job. Raw credentials are not stored in D1 or returned by the API. Meta/Instagram, TikTok, Google Ads, and YouTube use one-time, tenant-bound OAuth state and store only encrypted tokens plus sanitized account metadata. A provider remains visibly unavailable until Avendo's corresponding OAuth application credentials are configured.
Retention and compaction
Scheduled maintenance deletes expired raw Discover evidence from R2 while preserving its structured record, checksum, provenance, and audit history. Radar keeps the current landing-page capture and compacts raw historical snapshots after one year while retaining the structured diff. When the latest customer-supplied media license expires, Avendo redacts derived transcript, OCR, scene, pacing, production, and originality analysis; it does not silently delete the customer's original asset.
Analytical warehouse status
Avendo has provisioned an isolated EEUR R2 warehouse with Data Catalog enabled and a structured, Worker-only Cloudflare Pipelines stream. The orchestrator emits versioned first-party platform metrics, Radar pattern scores, experiment posteriors, and retention audits without raw credentials. The Parquet/Iceberg sink and R2 SQL query path remain unavailable until a separately scoped Cloudflare catalog provisioning token authorizes the sink; Avendo does not label that path live before the authorization and end-to-end query pass succeed.
Campaigns
Campaigns translate evidence into a goal, audience, offer, and distinct directions.
Each generated direction includes a name, hypothesis, angle, hook, script, cited evidence, diversity score, and risk. Directions are proposals until an approval record is created and decided.
New directions are generated through Cloudflare Workers AI with a strict JSON schema. Avendo rejects incomplete output, duplicate concepts, and evidence citations that do not exactly match the supplied Product Truth. Every successful plan stores its provider, model, job ID, schema version, timestamp, and evidence count; Approvals shows that provenance. A legacy direction without provenance is labeled plainly and can be replaced with Regenerate AI directions from Campaigns.
Studio
Studio turns an approved direction into a versioned creative project.
Before rendering
Confirm the proof, hook, CTA, destination, aspect ratio, captions, and intended channels.
After rendering
Review legibility, safe areas, claims, pacing, audio, and the final export before approval.
Open an approved campaign direction from Approvals to carry its campaign, direction, hook, angle, and script context into the editable Studio brief. A failed render returns to a retryable draft state and shows the real renderer error.
Generate scene media
Select a scene in an editable draft and write its visual direction. Generate image creates a new 9:16 image with Cloudflare's SDXL Lightning model. Once a rights-cleared image is assigned, Animate image uses it as the required first frame for Hailuo 2.3 Fast. The durable job continues if you leave the page, shows a real failure if the provider fails, and returns reserved units on failure.
Successful media is stored in the workspace asset library with the model, prompt, job, generation time, source image where applicable, and an AI-generated rights attestation. If the project is still an editable draft, Avendo creates a new project version and attaches the result to the selected scene automatically.
Launch
Launch keeps delivery state, approvals, schedules, receipts, and failures visible.
Avendo currently produces approval-gated export packages. The customer authorization layer is implemented, but direct Meta, TikTok, and YouTube delivery remains disabled until each provider application is configured and the write-scope flow, idempotency behavior, delivery receipts, and failure recovery pass production acceptance.
Learn and Analytics
Learning objects preserve useful outcomes for future campaign decisions.
Measured outcomes can be promoted into learning only when they have a clear source, metric, time window, and confidence. Avendo keeps estimates and forecasts separate from observed performance.
Freeze the variants
An experiment compares at least two immutable campaign-direction IDs against one declared primary metric.
Attribute outcomes
Send exposure and success events with the product, experiment, frozen variant, and a stable idempotency key. Avendo rejects variants outside the experiment.
Version the posterior
Every accepted event queues a durable Beta-Binomial analysis. The result stores exposures, successes, posterior mean, 95% credible interval, conservative probability-best, model version, and evidence boundary.
Review before transfer
A recommendation remains withheld until every variant has 50 exposures, the experiment has 100 total, the leading variant has at least 90% conservative probability, lift is positive, and its Radar pattern was accepted by a human.
First-party outcome contract
Customer apps and trusted agents can call the MCP record_product_event tool. Send one exposure when a user enters the frozen treatment and one success only when the declared primary outcome actually happens. Reuse the same product, experiment, assigned variant, and pseudonymous user ID; give every event a stable unique idempotency key.
{
"productId": "VOCALMAX_PRODUCT_UUID",
"experimentId": "FROZEN_EXPERIMENT_UUID",
"variantId": "ASSIGNED_VARIANT_UUID",
"eventRole": "success",
"name": "calibration_completed",
"occurredAt": "2026-08-24T18:42:00.000Z",
"anonymousId": "stable-pseudonymous-user-id",
"properties": { "surface": "first_calibration" },
"idempotencyKey": "vocalmax:calibration:UNIQUE_EVENT_UUID"
}For the named Vocalmax pilot, use calibration_completed as the success event. Do not send a success for opening the app, viewing the calibration, or clicking the CTA. Those may be observations, but they are not the experiment outcome.
Approvals
Approvals are the human control point between an AI proposal and operational use.
The resource is waiting for an authorized reviewer. It is not cleared for production use.
The reviewer accepted the resource for its next gate. This does not automatically publish it.
The resource returns to a revisable state. The decision and optional comment remain recorded.
The resource is not allowed to continue in its current form.
What the buttons do
Approve records the current user, decision time, and resource state. Product claims become available to campaign planning, campaign directions can move into Studio, creative projects become export-eligible, and store listings pass their publication gate. Request changes records the decision and returns the resource to a revision state.
Plans, production units, and credits
Generation uses a predictable Avendo unit balance instead of exposing provider billing directly to every workspace user.
Included allowance
Each plan includes a monthly production-unit allowance. Billing shows the current period, consumed units, active reservations, and remaining plan allowance. An image generation reserves 1 unit; a Hailuo video reserves 8 units.
Purchased credits
When the included allowance is exhausted, an owner or admin can buy a non-expiring credit pack through Stripe Checkout. Purchased credits are consumed only after the plan allowance and remain in the workspace wallet across billing periods.
Generation reserves units before the durable job starts. Success commits the debit. A provider failure or rejected job releases the reservation and returns any wallet-backed units. Stripe credits enter the wallet only after a signed webhook reports the Checkout payment as paid.
Which AI runs where
- Generative text: GLM 5.3 Flash for product reasoning, campaign planning, Creative DNA interpretation, outcome summaries, and review translation.
- Images: Stable Diffusion XL Lightning for original scene imagery.
- Video: Hailuo 2.3 Fast for animating a licensed first-frame image.
- Specialized processing: BGE embeddings and Whisper transcription remain specialized models rather than being replaced by a text model.
Autopilot
Autopilot is a permission policy for scheduled observation and recommendations, not unattended campaign delivery.
No scheduled evidence collection or first-party sync is queued by Autopilot.
Collects permitted public storefront and keyword observations and surfaces failures.
Adds reviewable scores and recommendations. It still cannot approve, publish, or change spend.
Private reviews and reports run only after the customer’s store credential is verified and first-party sync is explicitly enabled.
Outcome recommendations are immutable, versioned review records. A reviewer may accept one for controlled testing or dismiss it. Acceptance does not create a publication, authorize spend, or bypass the existing creative and launch approvals.
Notifications
Workspace events can be delivered in-app, by Cloudflare Email, and to browsers that the user explicitly subscribes.
Delivery controls
- Email delivery from notifications@avendo.io
- Per-device Web Push subscription with native browser permission
- Separate approval, workflow, system, and weekly-summary preferences
- A real delivery test in Settings
Events
- Approval decisions and requested changes
- Completed launch packages and store publication
- Workflow failures that require attention
- In-app history with read state and destination links
Push is opt-in per browser. Turning it on registers Avendo’s service worker and stores the browser’s encrypted push subscription; turning it off removes that device subscription.
Roles and permissions
Roles decide who can read, create, approve, publish, and manage the workspace.
Full workspace management, approvals, publishing controls, billing, and agent tokens.
Creates product and campaign work, decides approvals, and operates launch workflows.
Builds campaigns and assets, but cannot approve their own operational gate.
Reads product and campaign context and can decide approvals.
Read-only access to the evidence and current state.
Tips and troubleshooting
Small operating habits make the system faster, clearer, and safer.
Use canonical URLs
Submit the final public product page, not a redirect or private preview.
Wait for evidence
Keep the job ID. You can leave the page while the durable worker continues.
Refresh intentionally
Refresh after material product changes, not for every minor copy edit.
Keep claims narrow
Claims supported by one exact source are easier to review and reuse.
Separate signal from fact
A competitor pattern can inspire a test. It does not prove your product outcome.
Use request changes
Send weak work back with a clear correction instead of approving around the problem.
Analysis appears slow
The dashboard should show queued, running, progress, elapsed time, and a job ID. Use the job ID to check status. A real product capture can take around one minute because it includes browser capture, evidence extraction, storage, and indexing.
No claims were extracted
This is valid when the source does not contain a supportable marketing statement. Add a richer official source or improve the product page instead of inventing a claim.
A channel says unavailable or credential required
Public store observation works without owned credentials. Avendo owns the OAuth application and Cloudflare integration layer; each customer authorizes the developer account, app, ad account, or channel they want Avendo to operate. An App Store Connect key is normally scoped to the customer’s Apple developer team and role, then the FaceRestore app ID is bound to the workspace. Google Play uses a customer service account granted access to that app. Paid social uses customer OAuth authorization. Until a connection verifies, use the approval-gated export package.
Agents and MCP
The Avendo MCP lets trusted agents inspect workspace truth and create bounded work through the standard Streamable HTTP transport.
get_workspace_summarylist_productsget_product_truthlist_campaignslist_pending_approvalsget_job_statuslist_radar_intelligenceanalyze_productcreate_campaigncreate_radar_research_briefrecord_product_eventRadar briefs require a human-accepted pattern and approved Product Truth. Outcome events require a write token and immutable experiment linkage. Agents cannot approve, publish, bill, or delete through MCP.
Connect an agent
Create a scoped token. The secret is shown once and stored only as a hash.
{
"mcpServers": {
"avendo": {
"url": "https://avendo.io/mcp",
"headers": {
"Authorization": "Bearer YOUR_AVENDO_MCP_TOKEN"
}
}
}
}Security and privacy
Agent access uses expiring bearer tokens with workspace scope and role checks.
- Only a hash of each token is stored.
- The full secret is displayed once.
- Tokens inherit the creating user’s current workspace role.
- Read-only tokens cannot create products, campaigns, or jobs.
- Tokens can be revoked immediately from this page.
- Every MCP-created job is written to the audit trail.
For account, GDPR, California, retention, and cookie information, read the Privacy Policy, Cookie Policy, and Security overview.