Novemade

How we build

Eleven products. One shared production system.

Eleven products do not run alongside each other unless the expensive parts are shared. Research, production, release and measurement run through one internal system, so the fifth product costs less to launch than the first and is better informed when it does.

The loop

Nine stages, and the last one feeds the first.

Every product goes round the same circuit. The stages are named for what happens in them, which is why learning something and acting on it are two stages and not one.

  1. 01ResearchSignals and a per-product idea bank, scored for relevance before anything is made.
  2. 02DesignThe product decides its own voice, claims and boundaries. The system fills them in.
  3. 03BuildAssets, narration and captions assembled from each product’s own material.
  4. 04LocaliseEvery string in every language, with parity between catalogues checked rather than assumed.
  5. 05TestAutomated gates, then a person. Nothing reaches a queue unreviewed.
  6. 06PublishPer-platform packaging, with publishing deliberately held behind human approval.
  7. 07MeasureRelease and performance signals return to where the work was made.
  8. 08LearnWhat worked on one product is readable by the next one that asks.
  9. 09ImproveThe fix lands in the shared system, not in one product’s copy of it.

What the system guarantees

Automation is only useful if it is safe to re-run.

Most of the work in a production system is not making things. It is making sure that a retry, a crash or a duplicate trigger cannot do damage — which is what lets the rest be automatic.

Nothing publishes twice

Content and publish jobs are identified by deterministic hashes of their own inputs. A duplicate trigger, a retry or a crash-and-restart resolves to the same identity, so the system cannot double-render or double-post.

Retrying is always safe, which is what makes automation restartable.

A crash resumes, it does not restart

Every stage checkpoints its result before the next begins. A failure halfway through picks up from the last completed stage rather than repeating the expensive work behind it.

A long pipeline can fail without costing the whole run.

The system never learns a product’s name

Everything that varies by product — voice, content families, asset locations, rules about what may never be claimed — lives in that product’s own configuration. The shared code reads it and never references a product directly.

A new product is a configuration, not a fork.

Repetition is measured, not hoped for

Each piece carries a fingerprint of its topic, hook and script. New work is compared against that product’s recent history and rejected when it is too close, which sends the generator back for a different angle.

Volume without a feed that reads like one product talking to itself.

Failures are classified, not swallowed

External calls are retried with bounded backoff and sorted into transient, permanent and not-configured. A platform that has not been set up yet is a normal warning, never a crash and never a silent skip.

The difference between broken and not-yet-connected is always visible.

Quality gates run before a human looks

Generated output is checked automatically before it reaches a queue, including whether every scene used real product material rather than a placeholder. What a person reviews has already passed the mechanical tests.

Review time goes on judgement, not on catching obvious faults.

Bugs become tests, not folklore

The awkward failures — a template that mangles a topic already phrased as a question, an opener doubling a prefix — were each found by generating real output and reading it, then pinned by a regression test.

The same class of error cannot come back quietly.

A language is shipped whole or not offered

Catalogues are checked for parity against the reference language before a build passes, so a locale cannot ship with half its keys and an English sentence in the middle of a screen. Where a language needs more than text — a right-to-left layout, a longer compound word, a recorded voice — that is checked too, on the screen rather than in the file.

Ten, sixteen or twenty-nine languages, and no half-translated screen in any of them.

Every generated asset knows what made it

Assets produced by a model carry the model, its exact revision, its licence and the candidate set they were selected from, stored beside the file. Recorded audio carries its engine, its licence and the measurement its own QA scored it on. A capture set carries a hash per file.

A licence question years later is a lookup, not an investigation.

Human approval stays in the loop

The system prepares, packages and proposes. A person approves. Publishing is never fully autonomous, by design rather than by omission.

Scale without handing over editorial control.

Check it yourself

This website is built by the same discipline

Rather than describe the standard, here is what is enforced on the page you are reading now.

  • 01One brand definition generates every distributable mark, icon, favicon and social card. Nothing is exported by hand.
  • 02The asset pipeline refuses a screenshot that has no caption, so no image can ship without alt text.
  • 03The build fails if a product claims a store listing it does not have, or if a download count, rating or user number appears anywhere in the content.
  • 04Colour contrast is computed in a test against every surface it is painted on, in both themes.
  • 05A browser harness loads every route at eight widths and fails on horizontal overflow, on a collapsed mobile menu, and on a menu that will not close.
  • 06Internal links are crawled on every check, so a rename cannot quietly leave a dead link behind.
  • 07Every number this site states about its own catalogue is computed from the catalogue when it builds. A test fails the build if one is typed into a sentence by hand instead.
  • 08Every product must have a working demo, and that is asserted rather than assumed — adding a product without one fails the build.
  • 09A product may only show a LIVE badge if its store state says a listing is public, and only a public listing may produce a download button.

The line

What we do not publish

This page describes what the system does and what it produces. It does not describe how it is deployed. Hosts, endpoints, credentials, machine names, storage paths and security architecture stay private — not because they are interesting, but because publishing them would be careless. The public site and the internal systems share no credentials and no control path.