notrest

Platform

Not Rest Inc. · Platform · How the Operating System for Action works

An Operating System for Action turns an intention into a composition of capabilities that can be authorized, executed, verified against reality, and recomposed when the evidence changes. This page is how that system works — the architecture from the constitution, section by section, with an honest mark on every part.

LIVE — running today, with the link to check it.
BUILDING — partially shipped, under construction, stated as such.
EXPERIMENTAL — practiced in our own work, not a product.
VISION — designed on paper, not built.

The loop

Vision

Everything else is scaffolding for this shape:

INTENT
   ↓
DECOMPOSE
   ↓
DISCOVER
   ↓
COMPOSE
   ↓
AUTHORIZE
   ↓
ACT
   ↓
VERIFY
   ↓
LEARN
   ↓
RECOMPOSE

An intention arrives. It is decomposed into what must be true, matched to whoever or whatever can provide it, composed into the smallest sufficient organization, granted bounded authority, executed, checked against observable reality, learned from, and recomposed when the evidence moves. Persistence is not success; adaptation to truth is.

At economy scale — across companies, machines, capital, and institutions — this loop does not exist yet. A much smaller version of the same shape runs inside a single working session in our open-source harness: decompose, delegate, gate, prove, bank. That is a session, not an economy, and the difference is the whole build.

The action kernel

Building

At the center should be a small, durable kernel — the minimum infrastructure required to turn intention into action. Its first-class kernel objects:

Identity        Action
Capability      Claim
Agent           Evidence
Mission         Verification
Task            Event
Resource        Reputation
Permission      Organization
Contract        Capital

Everything more complex is meant to be built by composing these, and the kernel is meant to stay small enough to understand.

What exists today is a narrow instance of it. This site runs a kernel of its own: a per-visit capsule that gives a visit an identity, an append-only journal that accepts exactly five kinds of event — delegate, result, validate, effect, dispose — with server-set time and hard caps, and a receipts read over what was recorded. The agents it records are declared in public at /agents/index.json. That is Identity, Action, Event, and Claim, in one page, at one site's scale. The general kernel — sixteen objects, versioned, shared across missions and providers — is not built.

Authority is not capability

Live

An agent may be capable of an action without being authorized to take it. Authority is a composite, and it is infrastructure rather than an afterthought:

CAPABILITY
+
PERMISSION
+
BUDGET
+
APPROVAL

Autonomy without bounded authority is not intelligence; it is uncontrolled power. So authority here is declared before it is used, and the declaration is public.

Check it. Every agent behind this site publishes a contract at /agents/index.json — purpose, degree of agency, permitted effects, prohibited effects, budgets. Cookies, cross-site tracking, and authority-change are prohibited in every one of them. The concierge that drafts a message to us may never send it: sending is prohibited outright and approval-gated, so a draft opens in your own mail client and you press send. And the deploy gate refuses to ship the site at all if the code and the declarations disagree — a contradiction cannot reach production. The same discipline, written down and reusable, is the session harness: MIT, thirty-one skills, bounded delegation with receipts.

Verification: claim, evidence, verification

Building

An agent saying "factory complete" does not make a factory exist. The unit of truth is not the output; it is the state change:

CLAIM
+
EVIDENCE
+
VERIFICATION

Which means asking, every time: what observable state changed, what evidence supports it, who verified it, can the claim be falsified, and what remains uncertain. Every important outcome should carry a born-red falsifier — a falsifier written before the work begins, born red, waiting for evidence to turn it green.

What runs today is the small end of this. The conformance gate is a set of falsifiers written before each ship, exit-coded, refusing the deploy when one stays red; every added check ships with its own negative control, so a check that cannot fail is not accepted. The journal records validate events alongside the actions they judge. What does not run is the general engine: independent verifiers, cryptographic and third-party checks, sensor evidence, and reputation earned from verified outcomes rather than fluent language.

Memory that compounds

Experimental

Companies accumulate institutional memory and then lose it in the turnover. The system is meant to make that memory durable and reusable across missions: which supplier failed, which architecture scaled, which legal path created delays, which assumption was wrong, which combination of capabilities worked, which failure patterns recur. The long-term advantage is meant to be that the system learns from coordinated reality — not simply from text.

We practice this on ourselves before claiming it as a product. In the harness, findings from delegated work are machine-written to an append-only store with the transcript path attached, ledgers record what each delegation cost, and a session ends by writing the state a memoryless successor would need. It is a working practice with real records, and it is not yet memory that compounds across missions, providers, and years.

The four planes

Vision

The infrastructure separates four conceptual planes:

INTELLIGENCE PLANE      CONTROL PLANE
models                  identity
reasoning               permissions
planning                policy
prediction              orchestration
                        routing
                        governance

ECONOMIC PLANE          REALITY PLANE
budget                  humans · APIs · companies
pricing                 machines · documents
contracts               sensors · physical world
payments                evidence · verification
capital

Most AI companies compete primarily in the Intelligence Plane. The durable advantage should increasingly come from the other three, because models may commoditize while trusted identity, capability history, permission structure, economic coordination, verified outcomes, event memory, reputation, and cross-industry composition do not.

Today only fragments exist, and only in one plane: declared identity, permissions, and policy for the agents of a single site. Three planes are drawings.

The economy-scale layers

Vision

These are named plainly so nobody mistakes a design for a deliverable. None of the following exists:

The order matters, and it is deliberate: bounded authority before broad autonomy, substrate before ecosystem, kernel before marketplace. A roadmap that starts at the marketplace is infrastructure theater.

What is actually running

Live

The rule this page obeys is the one the architecture is for: a claim is not an outcome. Everything marked live is a link you can open right now; everything else says what it is. The receipts, entry by entry: Proof.