Architecture
Six layers, each a set of real subsystems. Objectives enter through the interfaces, become intelligence in cognition, pass governance, act through execution, and return as learning — on a foundation that isolates every organization and records everything.
L1
How people and systems reach the OS.
Mission-control view of objectives, world, strategy, execution and governance.
src/app/console · src/server/command-center.ts
Versioned API, scoped keys, signed webhooks and a generated SDK.
src/platform · sdk/typescript
Typed, signed exchanges with intelligence systems inside and outside the organization.
src/domain/protocol.ts · src/domain/protocol-engine.ts
L2
Turning intent into an intelligence architecture.
Persistent, versioned objectives with outcomes, constraints, risk, authority and success conditions.
src/domain/objective.ts · src/domain/objective-interpreter.ts · src/domain/objective-graph.ts
Typed entities, relationships and facts with provenance, confidence and freshness.
src/domain/world-model.ts
Testable claims whose belief moves only with evidence; explicit statements of what is not known.
src/domain/hypothesis.ts · src/domain/hypothesis-belief.ts · src/domain/uncertainty-engine.ts
Decides the architecture — entities, capabilities, permissions, plans, gates — or refuses.
src/domain/compiler.ts · src/domain/compiler-architecture.ts · src/domain/compiler-plan.ts
Scenarios, dry runs and counterfactuals, always labelled simulated.
src/domain/simulation.ts · src/domain/simulation-analysis.ts
L3
The boundaries autonomy operates within.
Versioned principles and rules; only people ratify or amend them.
src/domain/governance.ts · src/domain/governance-engine.ts
Who may do what, at which level of autonomy, earned by track record.
src/domain/authority.ts · src/domain/trust-engine.ts · src/domain/rbac.ts
Kill switches, rate limits, CSRF, CSP and secret handling at the edge.
src/security · src/middleware.ts
L4
Acting on reality through governed capabilities.
Durable runs with leases, retries, budgets, pause and resume.
src/domain/runtime-machine.ts · src/runtime
What an entity can do, with risk and verification, separate from how.
src/domain/capability.ts · src/domain/marketplace.ts
Integrations and external actions over an SSRF-safe transport.
src/reality · src/domain/reality-engine.ts · src/integrations
Routes each task to a model by complexity, cost and reliability.
src/domain/model-routing.ts · src/ai
L5
Getting better from what actually happened.
Scores outcomes against success conditions and baselines.
src/domain/evaluation.ts · src/domain/evaluation-scoring.ts
Episodic, strategic, organizational and negative memory with retrieval.
src/domain/memory-engine.ts · src/domain/memory-retrieval.ts
Separates what caused an outcome from what merely accompanied it.
src/domain/causal-engine.ts
Versioned, measured, reversible improvement of strategies and entities.
src/domain/evolution-lab.ts · src/domain/evolution-process.ts
Notices signals and reflects between runs; proposes, never acts alone.
src/domain/opportunity-engine.ts · src/domain/dream-engine.ts
L6
What everything else stands on.
Postgres with row-level security: every row belongs to exactly one organization.
supabase/migrations · src/database
An append-only record of everything that happened, in order.
src/domain/events.ts · src/server/events
Traces and plain-language explanations of every decision.
src/domain/observability-engine.ts · src/observability
Plans, limits and usage enforced before work happens.
src/domain/billing-engine.ts · src/billing
Invariants
Pure domain
The decision logic — compiler, governance, evaluation, evolution — is pure and deterministic, so every decision can be re-derived and audited.
Isolation in the database
Tenant isolation is enforced by row-level security, not by application code remembering to filter.
Human decisions in the database
Constitution, policy and approval decisions are refused by database triggers for any request made with an API key.
Append-only history
Events, decisions and versions are recorded, not overwritten. Nothing is silently rewritten.
Honest epistemics
Observed, estimated, simulated and predicted values are distinct types — never interchangeable.
Fail closed
Missing governance, missing evidence or an unavailable dependency stops the action rather than guessing.