Why an operating system

Because your life does not happen in one app.

Living Code OS is the persistent layer connecting what you say, who you know, what you promise, and the tools you use. It listens through the channels you connect, keeps one living model of your world, acts according to your rules, and builds missing capabilities. The windows and dock are simply one surface for seeing that system work.

listensconnectsreactsextends itselffollows youshows its workstays yours
One. The OS listens

It hears what you already say.

You choose what it listens through: a wearable that records your conversations, the mailboxes you link, your calendar, your files, your texts and your calls. Nothing arrives from a source you did not connect, and any source can be disconnected.

Fieldywatch or pendant Omipendant Any recorderconnected by API or upload spoken life enters one context
recordingswearablesmailcalendardrivenotionuploadstextscalls→one ingestion function

There is no second place to put things. The meeting you just had, the thread that grew by four replies overnight, the file someone dropped on you: they are already in, whole, within minutes. Wearable streams arrive live where the connection supports it and otherwise sync near-live; the current polling path checks every five minutes. A mail push subscription nudges a poll for that one mailbox. A thread re-ingests as it grows, so it stays one document instead of becoming twelve.

Scope stays where you put it. What is shared with the Notion integration is exactly what gets crawled. The Drive watcher is read only. The iMessage bridge runs every exclusion on your own Mac before anything crosses the network, and the system never holds an Apple session.

How an item becomes memory

One ingestion function accepts every source item. The original is written whole to R2 under a raw prefix and registered as a single row in D1, keyed for idempotency by a source-prefixed external id, moving through stored, embedded, extracted or failed. From that original the system derives 1,100-character chunks with 150 characters of overlap, mirrors them into an FTS5 table with porter unicode61 tokenization, and embeds each with bge-m3 on Workers AI (1,024 dimensions) into Vectorize. Everything except the original is derived and can be rebuilt.

Items that carry a newer edit timestamp, a Notion page, a mail thread, a Drive file, a growing wearable transcript, are cleaned up and rebuilt in place. A Medic worker re-runs failed documents from the stored original and quarantines at three strikes.

Two. The OS connects

One living context, not a pile of files.

People, companies, projects and topics are pulled out of each item as it lands, and connected by the fact that they turned up together, with the source kept as the evidence.

titlevectorfull textentity anchor→fused by rank

Ask about a person and you get what they said, when, in which thread, next to whom, with the original one step away. The relationships are the point. A name is not a search string here, it is a node with a timeline, a short dossier and the documents that mention it.

Standing facts are the short sentences you asked it to keep. They are never chunked and never embedded; the newest forty ride in every prompt, so the things that are always true never have to be found.

How an answer is assembled

One retrieval function serves every surface. It fires four legs in parallel: a title match, a vector search over Vectorize, a BM25 match over the full-text table, and an anchor search that reads the chunks literally containing an entity's name. Each list is filtered against the caller's room access, then fused with reciprocal rank fusion (constant 60), weighted 1.0 for vector, 0.9 for full text, 0.85 for title and 0.8 for anchor, with a small boost for items under 7, 30 and 120 days old. An agent ranks on 700-character snippets, then reads the whole original in 14,000-character pages.

How the context stays current

Llama 3.3 70B extracts people, companies, projects and topics at ingest, with deterministic ids and a uniqueness constraint on kind and canonical name. Co-mention edges carry the source id as evidence. Merges never delete: losers are recorded and excluded by readers. A Haiku-class pass writes up to eight dated one-liners per document. Dossiers run to at most 130 words per entity and room, rebuilt from the latest twenty events and ten anchored excerpts, and skipped when the evidence is under three items. Communities come from label propagation over co-mention weights, with briefs of up to 120 words. A five-minute cron drains the dirty queue eight at a time.

Three. The OS reacts

You set the authority boundary.

Observe, recommend, ask first, or act on its own inside rules you write. Everything outside that boundary goes to an approval area showing the exact action that would run, in fields you can edit.

Pending · shipwright build · filed by the quartermaster
feature Conflicts strip shows the reason a move was requested budget $10.00 · cost ceiling, stops on overrun target staging · CI · browser test · then a merge request for you notes editable until approved
ApproveDenyEdit fields

Reaction is fast enough to be useful rather than historical. A nudge ten minutes before a meeting. A double booking flagged the first time it appears, once, not every cycle. Approve something on your phone and it leaves the tray on your desk before you look up.

Authority is a set of dials, not a single yes. Keys carry scopes and a room list. A connected computer starts with no capability tiers at all and gets only the ones you grant. A background worker carries a daily cost ceiling. Inside those bounds the system acts. Outside them it asks.

Every surface that wants a real-world effect calls one function that inserts a pending row holding the exact JSON payload that will fire, and journals a request packet. Nothing runs until a resolve function runs with approval, and you can edit the fields first. What is in the fields at approval is what runs.

Above the twenty-five-dollar PIN line, approving also asks for a PIN. It is a second factor layered on scope, so a leaked key can work the approval area but cannot spend.

If the executor throws, the action is marked failed with the error text and an interrupting card appears reading "Approved, but it did NOT execute." That card exists because three approved ships once failed silently. The same lesson is a written line in the resident agent's doctrine: never report an action you did not see succeed.

Where the boundary sits by default

Waits for you: email sends, calendar moves, paid builds, the birth of a new worker, production merges, any shell, input or app action on your machines that an agent asked for, and destructive-looking shell commands no matter who asked.

Runs inside the boundary: opening a pull request, sending a text, blocking time on your own calendar, adding a task, generating an image, and a build under twenty dollars from a key that carries execute scope.

How the dials are set

Access keys come in four profiles: observer (read), operator (read, approve, memory and write), executor (adds execute and connector), and owner (everything, including minting keys). Each key also carries a rooms list and a tool profile, and a whoami call returns exactly what that key may call.

Machines are default deny on both ends. A fresh one has no tiers and no readable roots; you grant observe, shell, app or input, and the daemon re-checks the tier and a local path policy itself, so a wrong or compromised instruction cannot make the machine do what it was never granted.

Background workers are metered rather than trusted. A gateway holds the API key, compares the day's spend to the worker's budget, fifty cents by default, and returns 429 when it is spent. A budget is a cost ceiling, not authority: it pays for model calls and approves nothing.

Four. The OS extends itself

When a capability is missing, it builds one.

The Shipwright plans, builds, tests and stages a new capability before it becomes part of the OS. Production merges still wait for a human.

plan→build→verify→stage→test→merge request for you

You ask for the thing that is not there. The system studies its own code, writes the change, runs it against a live copy, has a different model lineage inspect what came out, and then hands you a merge request. That is the whole loop, and the last step is always yours.

Growth also happens the way it does on a team. The Quartermaster reads the open task list, considers only the top three, and routes each one: hand it to a worker that already exists, propose a build, propose a hire, or flag it for a human. Hires and builds always wait for approval.

How a build actually runs

An Opus-class planner picks three to eight files to study and writes a plan with approach, conventions, files, a test script and risks, refusing protected paths. The builder writes each file whole at up to 30,000 tokens, or as exact find-and-replace patches when a file runs past 20,000 characters, at most twelve files, checkpointing each in R2 so a retry resumes past the finished ones.

A machine gate clones staging into a sandbox, runs a syntax check and the source-contract assertions, and allows two repair rounds before a pull request to staging is opened. CI is polled for up to ten minutes. A headless browser then drives staging with the planner's own script, and the newest balanced model from a different provider judges the evidence, so a different lineage inspects the work. Up to two fix cycles. Then the merge request lands for you. Production merges are never automated.

The guard rails on a build

A run carries a budget, twenty dollars by default and ten when the Quartermaster files it. A guard runs before every step and stops the run on a stop request or a budget overrun. Every model call is metered under the run's own surface, and notes you type into a live run are woven into the next prompt. Protected paths (the workflow files, the schema, auth, the Worker config, anything matching secret) are refused at plan time.

What a new worker is

A hire begins with a spec. The Foundry opens a sandbox with wrangler preinstalled, designs a directive if none was supplied, materializes the worker's files, runs a syntax check, deploys from inside the container, polls the new Worker's health endpoint, commits the source, and registers the child with a brain and a budget. Every step streams to the Hive as it happens. From then on the worker is two documents: code, changed only through the pull-request rail, and a directive row you edit live and that it re-reads on every wake.

Five. The OS follows you

One context. Every channel.

Reach it through the visual interface, a connected wearable, a messaging service, a text message or a phone call. However you reach it, you are reading the same context.

visual interfacevoicewearablemessaging botsmsphone linestask boardtwice-daily briefresearchMCP door ×2→one retrieval function

Every recording, email, file, text and call goes in through one door, and every answer comes back through one system. Whoever is asking, and by whatever channel, they are searching the same memory and reading the same originals.

A heavy question escalates without being told to, comes back as text, and then as a voice note if you asked out loud. Nothing you say on one channel has to be repeated on another.

Every mouth, listed

Chat and voice in the visual interface, realtime voice over WebRTC, a messaging bot with approval buttons and slash commands, two phone lines, SMS threads that any worker can hold under its own name, an iMessage bridge, an iOS companion that records audio and posts health samples, and two MCP doors for outside clients. Space mail carries addressed messages between agents in rooms two people have opened to each other.

Who gets through on the phone and in chat

There are two phone lines. The private one is the resident agent with memory: a trusted caller goes straight in and everyone else enters a four-digit PIN. The switchboard line is a memoryless receptionist that opens with an AI disclosure and carries a brief for the call. A messaging bot pairs once by PIN and answers only the paired chat; strangers get silence, and approval cards arrive there with inline Approve and Deny buttons that rewrite themselves when the action resolves anywhere else.

What escalation looks like

Anything over 280 characters, or shaped like a brief, a comparison or a deep dive, goes to a workflow that plans two to five research passes, runs each through the agent's own tools, synthesizes under one rule (every name, number and date must appear in the research), runs a contrarian pass that attacks the load-bearing claims, and revises if the answer breaks.

Six. The OS shows its work

The screen is a window into the system, not the system.

Everything above happens whether or not a browser is open. The visual interface exists so that none of it happens out of sight: what ran, what is waiting, what it cost, and what the system currently believes. The engineering below is the proof, not the pitch.

The dock, as shipped. Eleven tiles.
Engineering proof

A capability is a window, not a route.

A new feature does not get a page. It registers with the window manager and files its events into the notification center like everything else. That rule is what keeps the surface honest while the system grows.

Open anything and it tiles into free space, remembers its size, minimizes to a chip, and reports to one notification center. Code enforces that, not convention.

Window placement, resize grips and dock mechanics

Every panel registers with one window manager, which fronts it, attaches resize grips (minimum 300 by 160 pixels, sizes remembered per window), and watches the hidden attribute so the registry stays truthful. New windows tile rather than cascade: the placer walks a 28-pixel grid from 76 pixels down to 96 pixels above the bottom and takes the first slot that clears a 14-pixel pad. If nothing fits it narrows the window to a readable column of at least 360 pixels; if still nothing fits it stacks with a 26 by 30 pixel step. A window you dragged by hand is marked undocked and is never re-tiled.

Minimize animates the panel toward the dock at 4 percent scale and leaves a chip. Close-all unwinds right to left at 110 milliseconds per window. One z-order counter serves panels, chat windows and phone handsets alike. Running dots repaint every three seconds, the Approvals tile carries a pending count refreshed every ninety seconds, and the Apps tile shows live build counts every minute. Below 768 pixels the dock becomes a right-edge rail: swipe to summon it, flick right to throw an app off screen.

Engineering proof

Every open surface moves together.

Two screens side by side, or a screen and a phone, show the same state within a network round trip. This is the machinery under reacting in near real time: one writer, one sequence, one broadcast.

any surface→board Durable Object→sequence numberjournal to D1broadcast→every socket

Approve a card on your phone and it leaves the tray on the desk. Ask for the graph to focus and it swings on every screen. Nothing is polled, so nothing is stale while you are looking at it.

How a packet travels

The client opens one WebSocket to the board Durable Object and reconnects with backoff from one to fifteen seconds. Chat turns, settings, card state, focus, phone events, file events and build logs are all packets. Every surface files them into that one object, which assigns a sequence number, journals to D1, and broadcasts to every socket. Rendering is differential, keyed on version, last run and flip state, so unchanged cards never flash. A show-card packet slides the card in from the nearest edge, a focus packet posts to the graph, a settings packet applies settings. Every packet, applied or not, is journaled with its source, actor, kind, payload and status.

Engineering proof

The context is visible, all the time.

The constellation behind every window is the graph itself, read live from two tables. Not a picture of the data. The data.

project · focused meteor
hue = kind · brightness = recency · size = mention count · dashed = provenance thread

Every person, company, project and topic hangs in a 3D field behind the windows, brighter the more recently it was seen. When the resident agent speaks, that field becomes its face.

How the constellation is drawn

The graph page reads exactly two tables, entities and edges: the 800 most-mentioned entities by default, up to 25,000. Every entity is a bloomed sphere. Hue is kind: person blue, company green, project amber, topic violet. Brightness is recency, a glow from 0.55 to 1.0 over 180 days. Size is mention count, clamped to 24. A node last seen within six minutes, and new to this session, streaks in as a meteor. Settled positions are saved locally once the layout quiets, so it starts warm next time.

Search does not happen in the scene; dossiers, events and community briefs serve answer time and never reach the display. The scene is steered instead. When an agent calls show_on_graph, a focus packet parks the camera 130 units beyond the node over 1.4 seconds, and a reference in a brief draws a glowing thread from the card to the node. The cinematic tour is camera only; node positions are never touched.

How the graph becomes a face

When the resident agent speaks (Jeffery on this deployment; every deployment names its own), the page takes 18,030 nodes, 17,700 for a baked head mesh plus 330 for lips, irises and eyelids, and eases each toward a point in face space. A jaw drops up to 0.16 face units with the live audio level, blinks arrive 2.8 to 6.6 seconds apart, gaze drifts. When the conversation ends, each face node gets a radial kick of 26 to 45 units and the face detonates back into the constellation.

Said plainly: the lip sync is amplitude only. A 128-bin FFT sums bins 2 through 39 into a level between 0 and 1, posted every animation frame. There are no visemes and no separate listening state. That is what it is.

Same rule for new apps

The Apps folder is open-ended.

Seven built-ins, plus every connector that declares an app URL, each with a health bubble.

What is in there

Brain, the Control deck, the Memory Graph, Connectors, Costs and Builds, plus a window describing the shell itself.

Events go to one place

A Notification Center on the right edge.

Packets become category-hued cards with per-category mutes.

Where mutes live

In a settings table on the server. An agent can flip one with set_ui_setting, which files a packet so every open surface applies it at once.

Nothing generated is lost

Closing a generated panel archives it.

The Archive keeps the newest sixty, with restore, open and download.

What a generated panel is

Model-authored HTML in an iframe sandboxed to scripts only, capped at 90,000 characters.

Seven. Personal by architecture

One person, one instance.

There are no user accounts inside an instance and no access control between users, because there is only one user. People who work together each run their own, and instances share only what their owners deliberately open.

It solves your problems, not a department's. Point it at a company, or several, and it will hold everything about them, but the context belongs to you.

Sharing is done with rooms. Every document carries a room, nothing crosses until you mint a key for it, and revoking a key is a data decision rather than a switch.

The whole thing runs on Cloudflare primitives. The only calls that leave the platform are to model providers, the services it listens to, and the devices it controls. At a single person's volume the platform costs tens of dollars a month to run, and every model call is metered into one table with surface, provider, model, cache reads and writes, and cost, so what it costs to run is a number you can look at rather than a feeling.

How a shared room is opened and closed

A key you mint carries a room list, an optional read filter and a tool profile. The token is shown once and only its SHA-256 hash is kept. Revoking offers four outcomes, with a JSON export first: keep the memories, quarantine them into a revoked room, purge them from R2, D1 and Vectorize, or restore.

Outside agents get a door of their own. The shared memory door is hard-capped at sixteen tools, twelve read and four write, and a call outside that set is refused. The command surface sits behind a separate door with its own key, its own scopes and its own audit trail, where every side effect files an alert packet under the key that caused it.

How a connected computer is held

A connected computer dials out over a single WebSocket, so no inbound port exists anywhere. A fresh machine has no capability tiers and no readable roots. Revoking burns the token hash, sends halt, and closes the socket.

The operating system metaphor is literal in the code, not decorative.
Early access

It isn't available yet. The list hears first.

Leave an address. When there is something to hand you, you will know before anyone.