Research Lab
Process.
Every stage can say no.
12 agent seats. One human. No one has to be watching it run.
It is not a straight line.
Review repeats until a round turns up nothing new. A failed guard sends the work back up rather than through. What the company learns returns to the seats that will use it next. Here is the whole shape.
Frontier officers.
12 seats. Each proposes in its own domain.
The gates.
Finance and Legal. Before anything else.
The panels.
Both sides argued. Consensus earned, never assumed.
Repeats until a round finds nothing new.
Every change passes here
The harness.
No path around this box. One guard fails and nothing ships.
Fails, and the work goes back up.
The ladder.
Promoted on evidence. Rolled back on trouble.
The human.
Nothing irreversible happens without them.
Returns to the top
The memory.
Lessons return as proposals, never writes. Only a signed approval makes one permanent.
What each part does
Frontier officers.
Each officer reviews its own domain on its own fixed cadence, most of them every week, and hands the founder one honest report. The Chief of Staff folds all of them into a single briefing.
The gates.
Finance guards the margin on every commit. Legal guards the public claims and the IP. Anything that touches money or a promise passes through them first.
The panels.
On the hard calls, expert agents argue both sides, and adversarial reviewers try to refute a finding before it is trusted. Consensus has to be earned.
The loops.
The two cycle marks on the chart above are this. Big plans face waves of adversarial review: independent finder agents attack, skeptic panels try to kill every finding, and the survivors get fixed before a line is built. Two rounds in a row that turn up nothing new is the only exit. The master execution plan behind this org survived eight rounds and 98 accepted findings.
The second opinion.
No single mind grades its own work, and no single family of minds does either. A rival AI from a different maker is brought in to check the big plans and argue the other side, because reviewers from one family share one family's blind spots. Its first official act was a dissent, and the dissent made the plan better.
The ladder.
Nothing new turns on by faith. A deterministic evaluator, a script with no AI in it, promotes new machinery stage by stage on committed evidence, rolls it back on trouble, and pauses everything when the human goes quiet. One kill-switch file stops the whole org.
The memory.
Knowledge lives in tiers: one small constitution every agent always carries, one operating agreement for how the seats work together, and each officer's own charter and lessons. No agent loads a peer's memory, so every mind stays lean. And no agent writes its own permanent memory: every lesson an agent draws is a proposal, and only the human's signed approval makes it part of how the company thinks. The rule is enforced by the same guards that block a failing commit.
The direction.
Autonomy here is earned, never granted. The design lets an agent graduate, lane by lane, from advising to acting, but only by proving a track record a human adjudicates. The destination is a company that increasingly runs, builds, and learns on its own, with one human guiding the system and holding every irreversible call.
The human.
One person makes every decision that matters and is accountable for it. The agents concentrate his attention. They never replace the call.
This is how this page, this company, the apps, the platform, the books, and the autonomous org itself were actually made.
The agent never commits.
Work enters through two doors and only two: a seat proposes into its own department file, or the human asks out loud and it becomes a numbered directive with an owner and a due date. A proposal that touches money without a cost line does not advance. Not flagged. Does not advance.
This is the first article of the thing that holds all of it up. The agent does the work. The workflow decides what survives. Before anything is staged, the tree is reset hard to where it started and everything the agent touched outside its declared lane is counted, then destroyed.
The agent is not issued a credential that could push. Not restricted from pushing. Not given one. The push happens later, from a different step, with a token that did not exist while the agent was running.
Nine of the seats can write reports and nothing else. The engineering seat can read every line of the product and can draft a pull request. It cannot merge one. That is not a setting. It is the shape of the lane.
Who may do what, in writing.
Every seat’s authority is a table in the repository, gated by default. Moving any lane to autonomous is a logged decision that has to name the criterion it met. The table below is rendered from the same file the workflows obey. 29 autonomous lanes. 40 gated ones. Merging to main appears in none of the autonomous lanes.
- SeatAloneThe human decides
Marketing
Alone
publish fused content; content proposals; reports.
The human decides
new pages; pricing or product claims; site architecture.
Finance
Alone
ledger updates; mechanical cost guards; analysis; reports.
The human decides
any spend; pricing change; billing change.
Engineering
Alone
engineering-health reports; tech-debt + architecture proposals; DRAFT PRs for new report-only audit dims, tests, and docs (never merged).
The human decides
merging any PR to main; money path; protected files; production or infra changes; app runtime code changes.
Product
Alone
product-health reports; prioritized backlog + roadmap proposals; feature and RFC outlines (as proposals).
The human decides
shipping any feature or code; pricing or the product model; anything user-facing.
Innovation
Alone
frontier innovation brief; high-conviction outside-the-box proposals.
The human decides
building anything (code, content, prototype, shipped surface); committing the company to a direction.
Operations
Alone
an operational + customer-experience point of view on a decision (advice only); a standing readiness brief (monthly, so the CEO can test the feedback).
The human decides
running any operation or touching support tooling; incident response, refunds, SLA commitments; anything customer-facing (it advises, it never acts) until it graduates at launch.
Revenue
Alone
a revenue point of view on a decision (advice only, never sets a price); a standing revenue-readiness brief (monthly, so the CEO can test the feedback).
The human decides
pricing, discounts, the tier model, any billing change (money path, human-approved forever); any spend, paid acquisition, or outbound sales action; touching Stripe or any commercial setting (it advises, it never acts).
Legal
Alone
a weekly legal-risk review (claims, IP, terms, privacy, compliance); flagging legal issues and drafting first-pass language, all as proposals for a human lawyer.
The human decides
giving binding legal advice or making a legal determination (a qualified human attorney does that; an AI cannot practice law); signing, filing, or agreeing to anything, ever; any contract, settlement, or regulatory action.
Quality
Alone
quality reports (the A-floor watch, test-pyramid health, regression watch); ratchet narration, retros, and heartbeat verification WITHIN the CEO-ratified ladder; strict-promotion proposals with evidence (flipping any gate stays a CEO decision).
The human decides
flipping any STRICT gate; changing gates, thresholds, or ladder criteria; anything outside the ratified ladder; any new stage or authority; protected files, the money path, merges, production or runtime code.
Security
Alone
security-posture reports and hardening proposals (once activated at launch); retro lessons to its own proposed lessons file.
The human decides
any change to runtime code, infra, or the money path; protected files; merges; incident response actions (it drafts the runbook step; a human executes); anything customer-facing.
Inspector General
Alone
reconciliation findings, committed to its reports_dir; reading any repo or production surface its battery covers.
The human decides
everything else: the seat reports and is deliberately unable to act.
Chief of Staff
Alone
synthesis, briefings, council, org-health.
The human decides
any operational authority (it is a staff role with no line authority; not the COO).
The decision ledger.
Governance you can check is governance written down. Every structural decision in this company’s life is a numbered entry in an append-only log, and the whole record is published here: 37 decisions, 2026-07-13 through 2026-08-11. Corrections are new entries that name what they supersede. Nothing is relitigated in place.
D-0001
2026-07-13
Found the autonomous company on the Marketing pattern.
D-0002
2026-07-13
Chief of Staff now, COO later: the title matches the authority.
D-0003
2026-07-13
Finance is a cross-cutting harness, not an advisory silo.
D-0004
2026-07-13
Cut the revenue seat pre-launch.
D-0005
2026-07-13
Add the trifecta (closed loop, preference learning, shadow mode) and an independent Inspector General.
D-0006
2026-07-13
Plug-and-play by law: a registry, a versioned additive interface, refined isolation.
D-0007
2026-07-13
Six-lens adversarial go or no-go: descope Phase 1.
D-0008
2026-07-13
Marketing conformance is Phase 1, an adapter rather than a rewrite.
D-0009
2026-07-13
Build Phase 1, the deterministic bedrock.
D-0010
2026-07-13
First live ledger population: the three seeded subscriptions are test data, revenue counts as zero.
D-0011
2026-07-13
Fixed the claim-truth violations the Engineering department surfaced.
D-0012
2026-07-13
Build departments ahead of launch, not after: Engineering and Product.
D-0013
2026-07-13
Add Innovation, a cross-cutting ideation seat that ships nothing.
D-0014
2026-07-13
Wind up the observer seats, Operations and Revenue. Supersedes D-0004.
D-0015
2026-07-13
The Chief of Staff coexists with the COO; it does not graduate into it. Amends D-0002.
D-0016
2026-07-13
The founding self-naming run and the public leadership page.
D-0017
2026-07-14
Add a General Counsel, the cross-cutting legal gate.
D-0018
2026-07-14
Interim data-processing posture: privacy claims scoped down to match the security page.
D-0019
2026-07-14
One consolidated CEO briefing; kill the standalone department emails.
D-0020
2026-07-14
The Board of Advisors: persona lenses, founder-ratified, dissent made structural.
D-0021
2026-07-14
The influences page ships indexed, on the founder's accepted risk.
D-0022
2026-07-20
The Memory Foundation: three-tier agent memory, locked.
D-0023
2026-07-20
The Quality seat is a separate seat, not a shared lens.
D-0024
2026-07-20
The Release Ratchet: stages activate work, never authority.
D-0025
2026-07-20
The recurring test carries a kill criterion.
D-0026
2026-07-20
The red-team layer, an influences elevation, and the outside-family checker.
D-0027
2026-07-20
The Vision joins Tier 0.
D-0028
2026-07-20
Convergence waived; the set ratified; Stage 0 authorized.
D-0029
2026-07-21
The vision document ratified and loaded.
D-0030
2026-07-21
Signing proves key custody, not personal presence: an accepted risk.
D-0031
2026-07-21
The token-efficiency lane, lane-first.
D-0032
2026-07-23
The observer is built inside the Inspector General rather than as a seat.
D-0033
2026-07-23
A writing bench, and simplicity promoted to always-on.
D-0034
2026-07-24
The Manuscript cabinet takes its fourth and last seat.
D-0035
2026-07-24
The Manuscript cabinet carries a trigger to cut itself.
D-0036
2026-07-29
The daily pulse is a third sanctioned emailer.
D-0037
2026-08-11
The Inspector General is a registered seat.
The raw dataset is one file at a stable URL: decision-ledger.json. CC BY 4.0, attribution required. Cite it as Orbyt Decision Ledger with the date. Ids, dates and supersession links are parsed from the committed log; titles are edited for publication, and the build fails if the two ever disagree on which entries exist.
83 dimensions. 104 guards.
The audit harness is what decides whether any of the rest is worth believing. 83 dimensions, each one a failure class somebody actually hit. Most report rather than block, on purpose, because a gate that fires constantly is a gate everyone learns to route around. A smaller set stops a commit dead, and it does not care whether the commit came from an agent or from the person who owns the company.
The rule that keeps it honest is not the count. It is that every guard has to be shown failing before it is trusted. A green check you have never watched go red is decoration. And every detector ships with a case it must NOT flag, because a guard that can only be proven loud has not been tested at all. The harness may even grow itself, agents adding report-only dimensions on their own, but turning one into a gate that can block a human takes a human signature, every time.
Every place it can say no.
The global kill switch.
One file. If docs/org/HALT exists, every autonomous seat stops before it spends anything. It is checked first, ahead of the token. It has never been used.
A halt for one seat.
The Inspector General, the seat whose job is auditing the others, has been halted since July 20, 2026 by a file the ladder itself has to clear. The org's own adversary is asleep, on purpose, until the ladder says otherwise.
The lane reset.
Anything an agent touched outside its allowlist is counted, then destroyed with a hard reset. Nine of the seats can only write reports. They cannot reach the product's code at all.
The guard gauntlet.
Guards run against the staged files before anything lands. The Chief of Staff seat has died here twice, both times over punctuation, once losing a full weekly briefing to three em dashes. Each death produced a mechanism rather than a note.
The sentinel.
An agent's output must end with its completion line, read from the tail of the result. No line means the run is assumed truncated and lands nothing, however good the work looked.
The founder going quiet.
If no signed commit from a human appears for fourteen days, promotions pause where they are. Signature status is read out of git, not asserted.
And the ladder, the stop that refuses itself, reading committed artifacts rather than asking anyone: It is holding at stage 1, with 1 of its own criterion unmet: zero discards. Read out of its state file on every build.
What it has not proven.
The organization writes its own performance review, so let it speak. This is from the Chief of Staff’s weekly briefing, unprompted, about the two worst defects in this company’s history.
It was you who found the defect first, not the org. So far the org has proven it documents its own mistakes well. It has not yet proven it catches them before you do.
That is the honest state. The agents do not write the product. One seat ships anything a reader can see, and it ships behind a typecheck, four guards, a full test suite and a production build. The self-improvement loop is switched off: seats may propose lessons, every proposal so far has been discarded by the gate, and the file where lessons would live still says none yet. 6 of 38 recorded runs have ended in failure, a share that is read out of the run ledger on every build rather than estimated in prose.
None of that is the argument against this. It is the argument for writing it down while it is still true, so that the version of this page a year from now has something to be measured against. See the receipts, or how the officers came to be.