An unsupported sentence is worse than no sentence
This is the design constraint the entire product is built around -- not a compliance afterthought bolted onto a drafting tool. Every claim in a report has a traceable source, and every judgment call surfaces to a human EP for sign-off instead of hiding behind fluent prose.
The hard prohibition
ESA Pro never generates the following unless it is present in your source material. Where it's missing, the report renders a [DATA REQUIRED: ...] placeholder instead of a plausible-sounding guess.
The same discipline applies to search radii: NPL at 1.0 mi and RCRA TSD at 0.5 mi are ASTM floors and are not editable. Every other reduction requires a written justification before it saves.
Not every source earns the same trust
T1-T5 tiers govern which lane a claim takes -- and T2-V, visual evidence, is treated as its own higher-scrutiny class.
High-reliability text sources
Eligible for the bulk-sourced lane -- one-pass verification.
Visual evidence
Sanborn maps, aerials, topo maps, recon photos. Always carries the source image itself, always individually reviewed -- never bulk-verified.
Unattributed information
E.g. interview info without clear attribution. Cannot alone support a REC.
Inferential
Always routes to the Review Queue lane.
Evolving issues -- PFAS, state programs, vapor intrusion guidance -- are never asserted from model memory. Those flag for human verification, every time.
Seven forced decision nodes -- no 'potential REC' category
Node-by-node reasoning is exposed, not compressed into a single confident-sounding paragraph. Every finding also carries an alternative hypothesis: what would have to be true for this classification to be wrong?
- 1Substance
- 2Nexus
- 3Limb
- 4De minimis
- 5Closure status
- 6HREC re-evaluation
- 7Confidence / gaps
Considered & Excluded log
Every condition-like observation gets a ledger entry even if immediately excluded -- e.g. "observed rusted drum, empty, no label, no staining -- excluded, no substance/nexus established." Omissions are a bigger risk than wrong claims, so there's a record of what was looked at and waved off, not just what made it into the report.
Structured coverage diff
For a finite structured source -- an EDR table listing 40 facilities, say -- source rows are counted against ledger entries referencing that table. A mismatch is a flag, no AI judgment required. Same idea for PDF page coverage: an agency file is 60 pages, extraction only cites pages 1-12 -- flagged.
A row for every source, including the ones that returned nothing
The standard's own test: "enough detail that a different EP could reconstruct the assessment."returned_records_count = 0is a valid, required value -- not silence.
source_idproject_idsource_namesource_typejurisdiction_fipsrequest_submitted_atrequest_filled_atsource_last_updated_atoriginal_source_last_updated_atreturned_records_countcurrency_daysaccess_methodendpoint_or_contactraw_payload_refApproved once. Changed only on the record.
Every Review Queue approval carries the reviewing EP's name, a timestamp, the claim ID, and a version -- immutable once made. A later change is a logged revision, never a silent edit. The report editor works the same way: "Apply Changes" opens a confirmation, then a VS Code-style diff, before anything commits as a new version. Rollback reaches any prior version, not just the last one.
Appendices assemble, and the EP Declaration gets signed, only after every Review Queue item is approved -- not before.
Five lenses, and fabrication is an automatic fail
Not a style pass -- an opposing-expert read before the report ever reaches an EP's desk. Each lens returns PASS, PASS WITH NOTES, or FAIL with specifics.
