Skip to content
Under the hood

How the machine works.

The operating model underneath the Action API — six surfaces, a practice-to-engine ladder, and the governed loop the company runs on. Written for the curious and for diligence; you never need it to buy an action.

01The bet

The bet.

One founder plus AI can operate a company that used to take 30 people — if the operating model is engineered as a system, not assembled ad hoc, prompt by prompt, every session. (leverage target — people a single founder can match with the os — Owner ruling, 2026-07-17)

2026 makes that credible. Context engineering is a named discipline. The integration substrate — MCP, open skill specs, durable execution — is real. The one-person company is no longer a thought experiment. (Owner ruling, 2026-07-17)

What AccelMars adds is the layer above the model: operating-model-level context engineering, a contract as the unit of work, deterministic integrity underneath it all, and a discipline for turning every recurring action into durable software. The model is rented. The system is the asset.

02The surfaces

Six surfaces.

Every operational question a company answers maps to a surface — and the engines that own it. Six, because each answers a different question.

Knowledge OS

What does the system know?

Externalized, structured memory — so the AI never restarts from zero. Tiered storage, context assembly, retrieval, and promotion of what proves useful.

Mind Cortex Canon Codex Lore Prism

Work OS

What is the system doing?

Work as an explicit primitive: contracts, planning, durable execution, and lifecycle enforcement — not ad-hoc prompts.

Forge Pact Orbit Cadence

People OS

Who is the system with?

The people of the company — hiring, deployment, competency, councils, and decisions — managed as first-class state.

Guild Warrant

Runtime OS

What does the system expose?

The composed binary — every engine behind one API, with shared routing, billing, rate-limiting, and observability. This is the Platform.

Gateway Conduit Relay

Infra OS

What does the system stand on?

Layer 0: deterministic, AI-free integrity. Reference-safe structure, canonicalization, the contract spec, and the delivery control plane.

Anchor Canon Booster Ledger Warden

Interaction OS

How is the system invoked?

The surfaces a human or agent touches — CLI, MCP, hooks, and automation recipes that turn intent into engine calls.

CLI · MCP · hooks · automation recipes

03The ladder

Nothing starts as an engine.

Every engine in the constellation began as a one-off action. When an action recurs it becomes a protocol; a proven protocol hardens into a pattern; a pattern worth automating becomes a skill, then a tool — and finally, when it's load-bearing enough, an engine.
Action Protocol Pattern Skill Tool Engine

The ladder is the discipline that converts daily work into compounding leverage — and the list of things not yet an engine is the roadmap.

04The packs

OS packs — the OS, pre-packed.

A pack is AccelMars OS composed with the engines for one job — the unit you install and license. Three tiers, from one engine’s power to a full product UI. The pattern is ratified; the roster is in design.
05The actors

Three kinds of actor. One rule.

AccelMars decides what runs on what — and the boundaries are the point.

Mechanical

Deterministic Rust at Layer 0 — reference integrity, structure, delivery. Fast, predictable, decade-stable, and AI-free by discipline. The floor everything stands on.

AI judgment

Above Layer 0, where ambiguity lives — routed through one gateway, provider-neutral, measured. Contextual and powerful, used exactly where its judgment earns its cost.

Human

At the boundaries: vision, taste, ratification, trust — the calls that can't be delegated. The human sets direction; the system executes at scale.

06The model

Inspectable core. Hosted edge.

The core is designed to pass the fork test — a partner could run the mechanical layer without us. Parts of the stack are already public on GitHub; which parts open, and when, is a deliberate per-engine decision, not a default.

The commercial layer is the hosted Platform — every engine behind one API. It already runs in production; pay-per-use access for teams who'd rather not self-host is opening up. Each engine also ships standalone. Open core, hosted runtime — the model that has worked for the infrastructure companies before us.

Open where ruled

Some specs, primitives, and engines are public today; each engine's open/closed line is decided on its own merits.

Private instance

The workspace where AccelMars runs its own company on the OS, every day.

Hosted Platform

The composed runtime at the edge — already running in production, with no infrastructure to operate.

07The self-building front

A system that builds itself.

The AccelMars OS has a conductor: a runtime that takes a goal, decomposes it into a dependency-ordered set of contracts, and dispatches each contract to a guild person — a named AI worker with a domain, a brief, and a memory. Every AI call is a guild person.

Each contract runs on cheap, owned models behind a provider-neutral gateway. The result is verified by a structural gate before the next contract activates. The cycle converges when the goal's invariants are satisfied. The cloud sandbox that hosts the work is destroy-when-idle — $0 when absent, $5 per contract, $20 per day as the budget caps.

The system has been live, end-to-end, since 2026-07-08. A goal like "ship a new engine crate" decomposes into a chain of contracts, dispatches each to a different guild person on owned models, and converges when the verify gate is satisfied. The cloud sandbox that hosts the work is destroy-when-idle — gone the moment contracts are settled, present only while work is in flight.

Goal → contracts

guild conduct takes a goal, materializes an orbit project, and emits the contract chain.

Guild people → verified

Each contract is dispatched to a named guild person via the FUSE trust gate, with a structured verify command. Failures retry, successes fold the outcome forward.

Cloud sandbox → destroyed

The work runs on a destroy-when-idle Fly sandbox (one region, iad) — present only while contracts are in flight, gone the rest of the time.

Attended, not autonomous. The conductor defaults to human-in-the-loop. Every cycle runs with a human approving the dispatch — the unattended trust ladder is being earned, not assumed. Until the ladder is earned, "self-building" means a single human shepherding a system that does the work.

A system built for leverage.

The Action API opens to its first callers soon — get early access, or explore the full engine catalog.