Conventional ad networks treat capacity as infinite so long as the card clears. Send a hundred leads to an operator already at ninety-five percent load and the whole system fails at once: staff burn out, service degrades, reviews collapse and the ad spend is wasted. Capacity has to be an input, not an afterthought.
Staff consistently over standard hours, unplanned leave spiking, queues backing up. Free organic prominence is withdrawn first and rotates to a competitor with room; paid bids are dialled back behind it.
Shift disengagement and context-switching are elevated. The business keeps the minimum volume it needs to survive; overflow is routed away until the signal recovers.
Shift density is comfortable and availability is high. Market prominence is amplified so the operator receives the volume required for steady, sustainable growth.
Devices compute differentially-private metrics locally. What leaves the premises is a single low-resolution state for the whole team — never a per-employee record, and never anything an employer can drill into.
| Workforce signal | Anonymised observation | State | Engine action |
|---|---|---|---|
| Work hour mean testing | Team consistently clocking around twenty percent over standard hours. | over_extended | Withdraw free top-of-page organic exposure first, then throttle paid bids. |
| Leave spikes | Statistically significant unplanned leave across a rolling fourteen days. | degraded | Demote high-volume organic lead generation and pause peak promotions. |
| Shift friction | Elevated context-switching and extended idle time during active shifts. | friction_high | Hold organic and paid exposure at survival baseline; route overflow to operators who can serve it. |
| Hour deficit | Team under standard hours with low shift density and high availability. | under_utilised | Grant organic prominence directly — volume arrives without the operator having to buy it — with paid reach optional on top. |
Workforce telemetry is the most dangerous input in the entire specification. RSP's guardrails are what make it usable at all — and if they cannot be met, the signal is simply not collected.
Employers never see individual scores, location traces, device habits or leave reasons. They see one business-level capacity index and how the engine is responding to it.
A signal is only generated where a team or site meets a minimum threshold of active workers, so no manager can isolate the impact of one person being unwell.
Raw telemetry is reduced on-device or at the edge to a low-resolution state and then destroyed. Nothing raw is transmitted or retained.
Participation is a grant, not a condition of employment, and withdrawing it removes the contribution without penalty to the individual.
A zero-knowledge accounting sync — tokenised feeds from mainstream accounting software or quarterly statements — establishes whether a business is under, at, or well past the growth pace it needs to stay healthy.
Actual velocity is ingested over a rolling ninety-day window. Target velocity is the sustainable pace established during calibration. A player far past target has their prominence rotated away; a player short of survival minimums has theirs lifted.
Why ranking by budget alone breaks markets — and what replaces it.
Rich real-time demand signals with the identifiable source burned on write.
Neutral, vertical-congruent feedback that acts as a relief valve.
The VES maths and how rotational prominence is calculated.
The 90-day sandbox, privacy guardrails and the case for adoption.