Rooms with something running in them.
A room is one project: its own repository, its own address, its own paper trail. Of roughly ninety of them, about forty hold a real running application and about eighteen are deployed to a public address. The rest are scaffolding, spec-stage, or retired — and saying so is more useful than a number that counts empty directories.
The full catalogue, and the stack underneath it →
As of 2026-08-20. Client work described by function only.
An operating system that acquired a constitution.
C10:OS is text-default and CLI-first, work organized into numbered rooms, every change carrying the reason it was made. What changed is the part nobody plans for at the start: the system got large enough that its own record became the thing most worth protecting — and a record anything can write to is not a record. So the machine grew a governing layer: ratified doctrine, an admission gate, an append-only ledger of crossings, and an evidence trail behind every claim. Nothing self-admits. Not a document, not a decision, not this page.
The rest of this page is that layer — the parts that make the work above repeatable rather than lucky.
Git records what changed. The chain records why.
Every command that changes state takes a --why and refuses without one. The reason lands in an append-only chain beside the commit, so the question that actually gets asked six months later — why is it like this? — has an answer that outlives whoever typed it. This is the oldest rule here and the one everything else was eventually built to protect.
Quoted from the chain, trimmed for length. Room and client identifiers withheld.
Nothing self-admits.
A rule of recognition never recognizes itself. Every admission rests on something it cannot itself admit — so the regress is terminated, not hidden, at a declared external anchor, and the machinery below it is split into two organs that check each other. Fuse them and "the evaluator computed it" starts to masquerade as legitimacy.
Holds the criteria
Applies the ratified tests and issues the verdict. It can only disqualify — its authority is delegated, never invented. It supplies governance, not a record.
Holds the ledger
Append-only, replayable log of crossings. It makes admission reproducible and accountable. It buys replayability, not authority. No record, no admission.
Holds the anchor
The founding act the graph cannot contain. It grounds admission and is never produced by it. A ratification is the sufficient step; eligibility is only necessary.
A crossing records an event, never a conclusion — that a probe ran, that a file was read, that a proposal was admitted. What the event establishes is a separate claim that references it and can be challenged on its own. That keeps the ledger a log of what happened rather than of what someone decided it meant.
26 candidate principles have been staged; 9 crossings are recorded; 35 assessments sit behind them. Objections are first-class and filed as their own records — and when none were raised, the ratification says so, because an empty objections folder must never be ambiguous between unused and unmet.
AI can ask. Only code decides.
Automation proposes constantly here. It never holds the pen on what leaves. A deterministic gate sits at the boundary: policy decides, and every crossing — allowed or refused — is written to a hash-chained, signed receipt ledger, so a refusal is as auditable as an approval. The layer that negotiates what an outside party needs is blind by construction: it can describe the requirement without ever seeing the data behind it.
No language model sits on the release path. Plans are checked against declared policy before execution, not reviewed for plausibility afterward.
The parts that don't bend.
Load-bearing, and still forming.
Load-bearing
- The reason chain — 4,050 entries, relied on daily
- Room scaffolding, gates, and recorded graduation
- Service registry with declared boot order
- Publishing rooms to their own addresses, access by email
- Fleet rollout by role, profile, and stage
- Session-bound identity resolution with a single resolver
Still forming
- Composition — which operator acts next is deliberately unresolved
- The governing layer is young: most doctrine sits in trial, with review triggers attached
- Egress receipts are live; hardening continues
- Machine-inferred proposals — the half of the loop barely exercised
The open question is named on purpose. Everything above defines what gets preserved and how; none of it defines what selects the next move. Hard-wiring a pipeline would close that cheaply and wrongly, so it stays open until the answer arrives as its own operator.