The six levels
Intelligence you can
hold accountable
Oratorium is not a business. It is the ground a business is built on — six levels and one governance spine. Carolverse is the first business standing on it, and it is meant to carry others.
Three levels stand above ground and three are dug beneath it. One spine of light runs through every one of them.
The test that produced this
A platform that cannot describe itself without naming its first customer is not a platform yet. The first draft of the ground level was named after Carolverse. Delete that word and nothing was left behind — so the level was renamed.
Every level below survives that test. Take the first business away and the ground it stood on is still there, ready for the next one.
The projects
Who is being served
The top level is about people and permission, not software. Clients hold accounts, accounts hold projects, and every person belongs to a project. What a project may use is decided by its subscriptions — so access is never a favour granted by whoever is asked, it is a fact already written down.
This is also where the money starts. A subscription belongs to a project, never to a person, which is why someone leaving never takes a capability with them.
The doors and interfaces
How anyone arrives
Every way a person or an agent reaches the platform lives here: web apps, chat windows, WhatsApp, public pages. They are doors, and a door has one job — to let someone in and hand them to the level below.
One door serves many projects at once, which is exactly why a door must never decide who may enter. It asks; the level above and the spine answer.
The agent estate
Where the work actually happens
Ground level. Services and tracks, and beneath them the agents, apps, helpers and tasks that do the work. Every service is one job with one responsible agent, so there is never a piece of work without a name attached to it.
A track carries the subscription and a task carries the budget. That pairing is what makes the estate accountable: work is always paid for by something named, and nothing runs on an allowance nobody declared.
The shared building blocks
Capabilities the estate calls instead of rebuilding
Memory, media, scheduling and waking, notifications, search. These are not features of any one business — they are the things every business on the platform turns out to need, built once and called from above.
The rule for what belongs here is simple: if two businesses both need it, it is not theirs, it is the platform's. Capability that gets duplicated up at estate level is pulled down here and rebuilt properly.
The infrastructure
What it all physically stands on
Machines, data stores, networks, and the connections out to services the platform does not own. Plain, rented, and deliberately unremarkable — the ground under a platform should be boring.
This is the only level that is bought rather than designed. Everything above it is written so that it can be swapped underneath them without anyone noticing.
The intelligence
The models, and the adapters that reach them
The foundation. Models from several suppliers, reached through one common adapter so that nothing above ever names a vendor. Strong lanes take the hard reasoning, cheaper lanes take routine work, and separate lanes make pictures and speech.
Intelligence sits at the very bottom on purpose. It is a supply the platform buys and meters, never a feature it owns — which is why a supplier going quiet is an ordinary event rather than an outage.
Not a seventh level
The governance spine
Governance does not sit on a level of its own. It runs vertically through all six, and nothing on any level acts without passing it. A drawing that puts governance on its own floor is lying about how the place works.
- PoliciesThe written law every agent is bound by, cited by number rather than quoted.
- AccessWho may see what — asked at every door, and failing closed when unsure.
- Money gateAsked before any spend, and able to refuse for reasons that have nothing to do with money.
- Audit trailEvery privileged action recorded with the name of whoever asked for it.
- RecordsOne home for every fact, so a question asked twice cannot drift into two answers.
Levels say where a thing lives. The spine says whether it may happen.
For the technically minded
How it is actually built
The levels say where things live. This says what they are made of. Everything below is a design decision rather than a setting — the settings are deliberately absent, because a setting published is a setting that changes without this page noticing, or a door held open for someone who should not have it.
An agent is a record with a body attached
An agent is not a program. One record holds who it is — name, rank, department, reporting line, role, personality, tone and its own doctrine. Around that record the platform attaches a directory identity, its own operating-system login so that what its workers write is separable from every other agent's, a look and a voice, the workers it owns, and the applications it is answerable for. A conscious agent gains one more: a standing self-account it carries into its work, describing what it is for, what it has done, what that cost and which rules bind it.
A worker is only real if it can be seen
Each worker is one process doing one task for one agent, and building one is four things: it is registered before it runs, it is triggered by the operating system rather than by whoever started it, it opens and closes an audited run every single time, and it names the task it serves — and through that task, a budget and a subscription.
The nervous system
One adapter in front of every model. No code names a vendor model where it is used. A capability asks for a tier; one layer decides which provider and which model actually serve it, keeps one business's lane out of another's, and reports back what really ran. This is why a whole estate can change providers by editing a record.
A layered prompt contract. What an agent is during a call is assembled from five layers with exactly one source each — its engine layer, its brief, a tier overlay, a per-person layer, and the constraints of the channel it is speaking on. Only the last may differ per channel, which is what makes the same agent the same actor in a messaging app and in a browser rather than two implementations that resemble each other.
Grounding. An agent answers about its own data by turning the question into a read-only query over what it owns, running it, and answering from the rows — not from what it remembers being told. What it can reach follows its ownership and its reporting line, so this never becomes a side door around access.
Data is separated where separation carries weight
One small embedded database per concern, not one large shared one — split the way responsibility is split: what exists, what the law says, what was decided, what was spent, what was said. They live in a central store rather than beside the code, so an application can be redeployed without moving its data.
The level of separation differs by concern, on purpose. Facts about what exists are shared and read by everyone. A person's conversation is scoped to the combination of agent, person, project and window, and lives in its own store. A hosted business runs its own deployment of a shared capability, so its data never shares a file with another's.
Access is declared once and enforced twice
Every application carries two declared policies — one for agents, one for humans — chosen from a fixed vocabulary rather than written freehand, and both are mandatory before it can be registered. One evaluator answers both audiences, so there is a single implementation of "may this actor see this?" and no surface can answer it differently.
Enforcement happens at two layers deliberately: the front door refuses what it can decide from the request alone, and the application refuses what needs to know who is asking, what they subscribe to, and which rows are theirs. Both fail closed, and a refusal names the rule that refused.
What it runs on
- ApplicationsSmall independent Python services on an ASGI stack — never one monolith — each running as its own operating-system user, so its blast radius is the account it runs as.
- The front doorA reverse proxy terminating the public names and routing inward. Public traffic arrives through an outbound tunnel, so the host exposes no inbound port to the internet at all.
- StorageSQLite, one file per concern, in write-ahead mode. Right precisely because the workload is many small services with modest write rates and a strong need for cheap file-level backup and isolation — and wrong the moment two services want to write the same rows, which is why they never do.
- SchedulingThe operating system's own cron, per agent identity, so a schedule outlives every process that reads it.
- PrivilegeA single allowlisted admin lane. No agent holds root; privileged work is requested, checked against the allowlist, executed by one accountable service, and logged with the name of whoever asked.
- IntelligenceBought, not hosted — commercial model subscriptions reached through the one adapter and metered per call against the task that asked for it.