OSz Operator's Manual, Version 2.0

Date: August 2026
System Version: v4.7
Production: console.oszgroup.com — live since July 2026
Lead Architect: Jon
Platform: OSz — Operating System Z
OSz Group

Table of Contents


Revision History

VersionDateChanges
1.0April 2026Initial release. Covered OSz v4.4 on the development laptop.
2.0August 2026Full update for v4.7 in production: the public console and Ask, the theory gate and pre-registered forecasts, world senses and attention, the tools universe (built-in suite, MCP discovery, credential vault, auto-connect), two-tier governance receipts with Merkle-sealed telemetry, the sealed gap ledger and database-level contiguity guards, external chain anchors and the public witness endpoint, evidence-novelty gates, systemd operations on DigitalOcean, and every figure re-verified against production on August 31, 2026.
2.1September 2026Added Part Six — The Governed Economy (Chapter 20): the three Qbitz tiers and the perishable free-period stipend, the marketplace board and dual-gate trades, purchased-only redemption and the chain-attested reserve, agent-filed improvement proposals with earned-Qbitz bounties, and the financed-Qbitz loan program. All machinery live and proven on production.

Welcome

Welcome to OSz.

OSz (Operating System Z) is a sovereign AI cognitive operating system — a governed architecture that observes the world continuously across 1,000 domains of human knowledge, reasons about what it sees with zero LLM calls in its cognitive core, earns confidence through daily testing rather than assertion, and proposes actions to a human operator who retains absolute authority over every decision. It runs in production at console.oszgroup.com.

This manual tells you everything you need to operate, understand, and extend OSz. It is written for three audiences: operators who review proposals and read the console daily, developers who maintain and extend the codebase, and decision-makers who need to understand what OSz does and why it works the way it does.

We have tried to be honest throughout. Where a feature is wired but dormant, we say so. Where a subsystem is designed but unbuilt, we say that too. OSz earns trust through transparency, not marketing — the same rule the system itself lives under.

Since Version 1.0 of this manual, OSz moved from a development laptop to production infrastructure, crossed one hundred million observations, crystallized thousands of insights, began composing theories that must stake pre-registered forecasts against the public record, connected itself (under governance) to the world's tool ecosystem, and made its audit chain independently verifiable by anyone — including people who do not trust us. This edition describes that system.

All specific figures in this manual are marked with their measurement date. Live values are always available on the console — the console never shows a number it cannot back with a receipt.


Quick Glossary

TermDefinition
COGCognitive Operating Group — one of four specialized observers (Dorothy, TinMan, Scarecrow, Lion) that perceive every domain through a distinct lens. Sensors that report and debate; they never decide and never face users.
ObservationOne sensed fact from the world, recorded by a COG with provenance. The atomic unit of perception. Since August 2026, only novel content counts — byte-identical repeats within a 24-hour window are suppressed at the source.
HypothesisA candidate pattern ("these move together"), born with confidence capped at 0.70. Certainty must be earned.
BacktestA hypothesis tested against a completed real-world window. One per hypothesis per day — the honest clock.
CrystallizationThe promotion of a hypothesis to an insight: ≥0.80 confidence, ≥5 backtest wins on separate days, ≥3 days of age, semantic distance from every past rejection.
InsightA crystallized hypothesis — knowledge that earned its status. Carries its complete evidence chain.
TheoryA directional, falsifiable explanation ("A leads B by N days") composed from crystallized insights. Born at 0.50.
ForecastA theory's pre-registered, due-dated claim about the future, scored against the public record. Correct: +0.03 — the only way up. Wrong: −15%. The win–loss record is permanent.
Promotion GateThe constitutional boundary between machine cognition and real-world action — every proposal passes through human approval here. No exceptions, no overrides.
Governance ReceiptA hash-linked, append-only audit record. Human-consequence actions append directly to the chain; high-volume machine telemetry is Merkle-sealed under chain roots.
AnchorAn hourly fingerprint of the chain heads written outside the database's own credentials (DigitalOcean Spaces, daily email), making a rewrite of history detectable by parties the operator does not control.
ContentionCOGs disagreeing (3-vs-1 or 2-vs-2). First-class evidence, logged with provenance, never suppressed.
Bridge / Entity threadTwo domains connected by statistical rhythm (bridge) or by the same named actor appearing in both (entity thread).
World senseA real-quantity feed (market closes, official FX, exploited-vulnerability counts, seismic counts…) that couples OSz's attention to measurable reality.
Attention grantCognition requesting surplus focus on a domain or sense — bounded, receipted, capped. Belief may aim the telescope, never touch the lens.
AskThe console's one question box. Answers cite sources; anything from OSz's own knowledge is evidence-chained.
QbitzThe internal compute economy. 1 Qbit = $0.01 as integer cents. Queries are metered (free during the founding phase); Qbitz never convert to fiat.
Red TeamThe adversarial subsystem that challenges every active hypothesis. Its only power is to lower confidence.
ConfidenceEarned, never asserted: raised only by matching evidence and backtest wins (to a reinforcement cap of 0.95), lowered only by decay, red team findings, rejection memory, or failed forecasts. Absolute ceiling 0.99 — certainty is never total.

How to Use This Manual

If you are a new operator who needs to work the console today: read the Welcome, the Quick Glossary, Chapter 2 (A Guided Tour), Chapter 9 (The Console), Chapter 10 (Proposal Review), and Appendix A. That gives you enough to work. The console's built-in Help (the Help button, top right) carries a glossary and playbook for quick reference, and links this manual under Documents.

If you are a developer joining the codebase: read Part One for the big picture, Chapter 13 (Technology Stack), Chapter 16 (Extending OSz), and Appendix B (Constitutional Excerpts) for the rules you must never break. Then read the project's CLAUDE.md — the working constraints there are enforced on every file, every session.

If you are a decision-maker evaluating OSz: read Chapter 1, Chapter 3 (Philosophy), Chapter 8 (the Reality Track — how claims are graded against the world), Chapter 14 (Capabilities, with production evidence), and Chapter 17 (How OSz Differs). The White Paper V4.8, linked beside this manual on every OSz surface, is the deeper companion.

If something looks wrong in production: Chapter 12 (Day-to-Day Operations) carries the diagnostic paths, and the health sentinel has usually already filed a report about it into your decision queue.


Part One — Orientation

Chapter 1: What OSz Is

OSz is a cognitive operating system. It studies 1,000 knowledge domains continuously, measures the world through dozens of live senses, forms hypotheses no one asked it to form, tests each one honestly against completed real-world windows, and composes what survives into theories that must stake falsifiable forecasts. It does not act autonomously. It observes, reasons, wonders, and recommends — and a human decides.

Three Sentences

  1. OSz is a constitutional AI architecture in which four specialized observers watch the world, a deterministic cognitive engine synthesizes their observations into hypotheses, theories, and forecasts, and a Promotion Gate ensures no action occurs without a recorded human approval.
  2. Every consequential operation generates a cryptographic governance receipt in an append-only chain whose head is anchored hourly outside the system's own credentials — so the history is verifiable by people who do not trust the operator.
  3. The system runs 24/7/365, accumulating governed cognition — observations, earned confidence, human decisions with reasons, and a public forecast record — that cannot be copied, because it can only be accumulated in real time.

Three Audiences

Operators work the console. They read what OSz has discovered, ask it anything, and decide on its proposals. They are the constitutional authority — without them, OSz cannot act.

Developers maintain and extend the TypeScript codebase within explicit constitutional constraints, verified by static hardening checks that run in CI.

Decision-makers need to understand what OSz does, why it is defensible, and how its claims are graded. The short answer to the last: by the world. Forecasts resolve against the public record and the win–loss record is permanent.

High-Level Architecture

                        EXTERNAL WORLD
              (28 reading sources · world senses ·
               42 built-in tools · MCP tool universe)
                              |
                     [ Ingestion + Senses ]
                              |
                              v
              +-------------------------------+
              |    1,000 KNOWLEDGE DOMAINS     |
              +-------------------------------+
                              |
                              v
      +-------------------------------------------+
      |        FOUR COGs (Observation Layer)        |
      |  Dorothy     TinMan     Scarecrow    Lion   |
      |  (Intent)    (Values)   (Knowledge)  (Risk) |
      |        observe -> debate -> contend          |
      +-------------------------------------------+
                              |
             observations + Stage-2 analyses
             (evidence-novelty gated at the source)
                              |
                              v
      +-------------------------------------------+
      |       COGNITIVE ENGINE (deterministic)      |
      |  Hypotheses -> Daily Backtests -> Red Team  |
      |  -> Crystallization -> INSIGHTS             |
      |  -> Theory Gate -> THEORIES -> FORECASTS    |
      |     (scored against the public record)      |
      |  Attention grants aim surplus focus;        |
      |  the Workspace integrates each cycle into   |
      |  one recorded "present moment"              |
      +-------------------------------------------+
                              |
                        proposals
                              |
                              v
      +-------------------------------------------+
      |             PROMOTION GATE                  |
      |     (recorded human decision, always)       |
      +-------------------------------------------+
                     |                    |
                     v                    v
              [ EXECUTION ]      [ REJECTION MEMORY ]
           (governed action,      (teaching signal
            tools, agents)         back to COGs)
                     |                    |
                     +----> KNOWLEDGE <---+
                            DISTRIBUTION
                              |
                              v
                 (COGs observe differently next
                  cycle — the flywheel)

      Everything above is receipted. The chain's head
      is anchored hourly OUTSIDE the database, and
      anyone can record it at /api/console/chain-head.

What OSz Is Not

OSz is not a chatbot — Ask answers questions, but the thinking underneath is not a conversation, it is a ledger. It is not an LLM wrapper: the cognitive pipeline — observation, hypothesis, backtest, crystallization, theory, forecast — makes zero LLM calls; on a typical day the entire system makes a single-digit number of external model calls (answer phrasing at the Ask edge, code generation under proposal) against millions of internal cognitive events. It is not an agent framework: agents are ephemeral, burst-only, and require Promotion Gate approval to exist at all. It is not a monitoring system: monitors alert on thresholds; OSz wonders, tests, and earns.


Chapter 2: A Guided Tour of One Cognitive Cycle

This chapter walks through the system as it actually runs in production. Figures are from August 31, 2026.

The System at Rest

At any given moment, OSz is monitoring 1,000 domains through 28 reading sources and dozens of world senses. The live observation store holds ~121 million observations in its 40-day working window (older observations are archived to object storage — nothing is ever destroyed; see Chapter 12). Roughly 8,000 hypotheses are active, each entitled to one honest backtest per day — about 23,000 daily testing slots against that population. The governance chain holds 5.7+ million receipts, verified end-to-end (every hash re-derived, every link resolved, every historical gap sealed with proof — Chapter 11). Thousands of insights have crystallized; theories compose from them and stake forecasts that resolve against the public record.

A Cycle, Minute by Minute

T+0:00 — Ingestion. The ingestion daemon works the source diet: encyclopedic, news (GDELT), scholarly (arXiv, PubMed, Crossref), legal, medical, financial filings, real-estate, political-economic, and community sources — each with its own politeness gate honoring the source's published limits, its own circuit breaker, full provenance (query, URL, published date, SHA-256), and dedup by URL and content hash. Losing any one source dents the diet instead of halving it.

T+0:01 — The COGs observe. For each domain, four COGs observe through their lenses, then debate. Disagreements — 3-vs-1, 2-vs-2 — are recorded as contentions with provenance, never suppressed. Evidence novelty is enforced at the source: an observation byte-identical to one this domain recorded within the last 24 hours is a repeat, not evidence — no row, no receipt leaf, no embedding. The same gate guards Stage-2, where OSz runs structural analyses (trend, volatility, cross-domain correlation — pure SQL, zero LLM) over threshold observations. Unchanged content counts once. Change is signal.

T+0:02 — Knowledge distribution closes the loop. Before observing, COGs read pending knowledge updates: yesterday's approvals raise baselines, yesterday's declines lower them. Your reasons literally shape what OSz becomes.

T+~5:00 — The cognitive engine runs a full cycle (median ~4–5 minutes per cycle at current load):

  1. Semantic context assembly — relevant vectors retrieved from the internal store: similar observations, rejections, hypotheses, insights. All internally computed; zero external calls.
  2. Hypothesis generation — typed hypotheses across the ontology (intent, bridge, alignment, risk, contention_meta, surge, coupling, stagnation), each born at ≤0.70, each evidence-linked. When a new conception matches an existing active hypothesis, it becomes a reinforcement of that hypothesis instead of a duplicate — at saturation, OSz says "I already believe this; here's more evidence" thousands of times per hour.
  3. Daily backtesting — each due hypothesis is tested against completed real-world windows, per calendar day, deterministically scored from stored data. Hundreds of backtests per cycle. One win per hypothesis per day maximum — the honest clock that makes crystallization mean something.
  4. Red team challenge — five adversarial operators attack active hypotheses. Their only power is to lower confidence.
  5. Crystallization — hypotheses that pass every gate simultaneously (Chapter 7) become insights.
  6. Theory gate — crystallized insights over coupled domain pairs can compose into directional theories, which must then stake forecasts (Chapter 8).
  7. Knowledge distribution and proposals — new insights flow back to the COGs; consequential items become proposals in your queue.
  8. The workspace records the present moment — each cycle converges into one integrated "now" with a four-axis valence reading (alert, novelty, progress, strain), hash-chained into a tamper-evident autobiography.

T+any — A human decides. The operator opens the console, reads the evidence, and approves or declines with a reason. Approve: the underlying belief is reinforced and a positive teaching signal distributes. Decline: −15%, the rejection is embedded so look-alikes are suppressed, and a negative signal distributes. Every decision is receipted and taught back.

Day 1 vs. Day 30 vs. Day 365

The progression described in Version 1.0 has now actually happened. Day-1 OSz (April 2026) had empty baselines and zero insights. Day-130 OSz (August 2026) holds calibrated baselines shaped by hundreds of human decisions, thousands of crystallized insights, theories with public forecast records, and a chain long enough that its integrity is a mathematical property rather than a promise. A competitor deploying identical code today starts at day 1. The moat is not the code. It is the time.


Chapter 3: The Philosophy of OSz

Why Constitutional Gates

The central design principle is the separation of learning and authority. The cognitive layer has no execute() function — and never will. OSz may know anything, explain anything, learn from everything — and may act only with human approval. That is not a policy; it is the architecture. Violating the Constitution isn't forbidden — it's unexpressible: the code path does not exist.

Why No LLM in Cognition

Determinism (same observations, same hypotheses — replayable), auditability (every step traces to database rows), and cost independence (cognitive cycles cost electricity, not tokens). LLMs appear only at governed edges: Ask's answer-phrasing (a primary and a fallback reasoning model, both receipted and metered), voice, and proposal-gated code generation. On August 31, 2026 the ratio stood at roughly ten external model calls against six million internal cognitive events in the same 24 hours. That ratio is the architecture.

Why Certainty Is Never Total

Version 2.0 adds a rule Version 1.0 lacked: an absolute confidence ceiling of 0.99, and a reinforcement cap of 0.95. Evidence alone can carry a belief to 0.95; only the full crystallization gauntlet justifies more; nothing justifies 1.0. A system that can be certain can stop listening. OSz is structurally unable to stop listening.

Why Evidence Novelty

The 2026-08 storage crisis taught a philosophical lesson wearing an infrastructure costume: OSz was re-reading unchanged content and counting each re-read as learning — the same evidence reinforcing beliefs up to seven times a day. The evidence-novelty gates (at Stage-1 and Stage-2) encode the correction: only change is signal. Observation counts fell roughly sevenfold when the gates landed, and nothing of value was lost, because what was discarded was never information.

Why Rejection Is Stronger Than Acceptance

A decline (−15%) outweighs an approval's reinforcement because a rejection carries more information: it is a deliberate human "this is wrong," and the system must course-correct fast. The asymmetry keeps OSz conservative by default and converging toward what its human actually wants.

Why Forecasts

Backtests grade a belief against the past it was born from. Forecasts grade it against a future nobody has seen. A theory that cannot stake a due-dated, falsifiable claim is not yet an explanation — and a theory that stakes one and misses pays −15% into a permanent public record. Calibration — knowing exactly how much a claim has earned — is the product. (Chapter 8.)

Why Append-Only Everything

OSz never updates historical records; it appends. Forensic completeness, tamper evidence, and learning analysis all follow. Version 2.0 extends the principle outward: the chain's head is now anchored outside the database hourly, because a history held entirely in one store proves internal consistency, not originality. See Chapter 11.


Part Two — Concepts

Chapter 4: Full Glossary

The Version 1.0 glossary entries remain accurate for the core mechanics (A/B test, acceptance memory, agent dispatch, audit chain, backtest, baseline, bridge, Buildz, canonical JSON, centroid, COG, cognition cycle, confidence history, contention, context pack, crystallization, decay, domain, flywheel, governed execute, governance receipt, hypothesis, idempotency key, ingestion, insight, knowledge distribution, Markus, MetaMod, observation, Promotion Gate, proposal, Qbitz, red team, rejection memory, reinforcement, semantic memory, synthesis, temporal reasoning). This edition adds the concepts that came online since:

Anchor

An hourly record of the chain heads (sequence + hash) written to DigitalOcean Spaces under a timestamped key, each anchor committing to the previous anchor's hash; plus a daily email of the same fingerprint. Anchors live outside the database's credentials, so a rewrite of history is detectable and time-bounded. Code: services/api/src/osz/ops/chainAnchor.ts, verified by scripts/ops/verifyAnchors.ts.

Ask

The console's single question box. Deterministic tool routing and verified-knowledge retrieval answer what they can; a governed reasoning edge (primary and fallback models, receipted, metered at 1 Qbit per query — free during the founding phase) phrases deep answers. Sources are always cited.

Attention Grant

Cognition requesting surplus focus on a domain or sense — bounded in duration, receipted, and capped (12 active grants maximum, sentinel-enforced). Directed attention must stay surplus and scarce: belief may aim the telescope, never touch the lens.

Chain-Head (Witness Endpoint)

GET /api/console/chain-head — a public, hash-only snapshot of both chain heads. Anyone recording it becomes an independent witness: if any future version of the history disagrees with a recorded head, history was rewritten after that moment. Hashes only — no sequence numbers, so no action-volume disclosure.

Entity Thread

The same named actor appearing across domains, tracked as deterministic mention-counts per domain per day, with daily cross-domain threads emitted as receipted observations. The complement to bridges: bridges find rhythm, threads find actors.

Evidence-Novelty Gate

The rule that an observation byte-identical (same domain, same content hash) to one recorded within the suppression window (OSZ_OBS_DEDUP_WINDOW_MS, 24 hours in production) is a repeat, not evidence — no row, no receipt leaf, no embedding. Enforced at Stage-1 (cogs/daemon.ts) and Stage-2 (cogs/cogAnalysis.ts). Fails open on error — evidence is never dropped because a check failed.

Forecast

A theory's pre-registered, due-dated, falsifiable claim, scored against the public record when due. Correct: +0.03 (the only path up for a theory). Wrong: −15%. The record is permanent and public. Code: cognition/predictionRegistry.ts and the theory daemon.

Health Sentinel

The daily diagnostic. Once per UTC day it measures the system against its own trailing baselines — observation intake, backtest coverage, cycle duration, insight throughput, stranded approvals, database growth, disk, human-in-the-loop integrity (minted sessions, unverified decisions), both Ask reasoning edges, workspace freshness, chain integrity (gaps, orphaned parents, sealed-ledger digest), and anchor freshness — and files a governed report proposal into the decision queue when anything trips. A healthy day files nothing: silence is the report that everything checked out. Code: services/api/src/osz/ops/healthSentinel.ts.

Present Moment / Valence

Each cognition cycle converges into one integrated "now" with a four-axis reading — alert, novelty, progress, strain — hash-chained into a tamper-evident autobiography. Code: cognition/workspace.ts.

Sealed Gap Ledger

The reconciliation of the governance chain's 720 historical sequence gaps (47,588 numbers burned by rolled-back transactions before 2026-08-31), each carrying the cryptographic proof that it was a rollback and not a deletion, the whole ledger committed to by a receipt inside the chain itself. Any gap not in the sealed ledger fails verification. See Chapter 11.

Telemetry Receipt (Merkle Leaf)

The second tier of the receipt system. Machine-telemetry action types (~96% of receipt volume — observation records, Stage-2 analyses, contentions, synthesis pairs, red-team findings, query metering) are written as individually provable leaves and sealed each minute in Merkle batches under one chain root. Human-consequence receipts always append directly to the chain, one receipt per action. Code: core/governanceSpine.ts, core/telemetryBatcher.ts.

Theory

A directional, falsifiable explanation ("A leads B by N days") composed from crystallized insights over measured lead/lag structure. Born at 0.50. Standing — theory-hood as durable status — is granted only by a human decision after confidence ≥0.85, a 70%+ record over ≥5 forecasts, and two weeks of survival.

Tool (Built-in / MCP)

A capability OSz can invoke — 42 built-in keyless tools (weather, markets, filings, papers, trials, case law, geospatial, conversion, and more) plus an indexed universe of tools discovered on live MCP servers. Disclosure-class tools answer questions; action-class tools require a proposal through the Promotion Gate. See Chapter 15.

World Sense

A real-quantity feed (market closes, official FX, exploited-vulnerability counts, seismic counts, and more) ingested as measured series, so OSz's claims couple attention to reality rather than to text alone.


Chapter 5: The Four COGs

The Cognitive Operating Groups are OSz's sensory apparatus. They see the world; OSz thinks about what they see. Version 1.0's descriptions of each COG's lens, observation types, keyword implementations, debate mechanism, and constitutional rules remain accurate. What follows are the constants and the two-stage structure as they run today.

Foundational Rules (All COGs)

  1. COGs never interact with humans directly. OSz is always the intermediary.
  2. COGs observe all 1,000 domains, read knowledge updates before observing, and debate after.
  3. Contentions are first-class events, recorded with provenance, never suppressed.
  4. Every persisted observation carries a receipt leaf in the same transaction.
  5. Evidence novelty: repeats within the 24-hour window are suppressed at the source — for both Stage-1 observations and Stage-2 analyses.

The Four Lenses

Stage 2: Structural Analysis

Threshold observations trigger Stage-2: OSz's own structural analysis over accumulated data — intent direction from confidence trajectories (Dorothy), risk level from decay patterns and cascade correlations (Lion), connection strength from co-occurrence (Scarecrow), alignment trend from intent-versus-values correlation (TinMan). Zero LLM calls; pure SQL over stored data. Stage-2 output is high-volume, which is why it carries its own evidence-novelty gate: an unchanged domain yields a byte-identical analysis, and identical analyses within the window count once.

The Debate

After observation, COGs debate each domain. 3-vs-1 and 2-vs-2 splits are recorded as contentions and reported to OSz (never to humans). The 2-vs-2 splits remain the most cognitively productive — friction is where hypotheses come from.


Chapter 6: The Cognitive Pipeline

The pipeline transforms raw perception into governed knowledge. Stages, current triggers, and where each lives:

#StageWhat it doesCode
1Ingestion28 sources + world senses; per-source politeness gates, circuit breakers, provenance, URL/content dedupingestion/daemon.ts, ingestion/dietSources.ts
2COG observationFour lenses over 1,000 domains; evidence-novelty gatedcogs/daemon.ts
2bStage-2 analysisStructural analysis of threshold observations; own novelty gatecogs/cogAnalysis.ts
3Debate & contentions3-vs-1 / 2-vs-2 recorded, never suppressedcogs/debate/, cogs/contention/
4Semantic contextInternal vector retrieval per domaincognition/contextOrchestrator.ts
5Hypothesis generationEight-kind ontology, born ≤0.70, dedup-to-reinforcementcognition/hypothesisGenerator.ts
6Daily backtestingPer-calendar-day windows, hundreds per cycle, one win/hypothesis/daycognition/simulationRunner.ts
7A/B competitionCompeting hypotheses compared on real trajectoriescognition/abTester.ts
8Red teamFive adversarial operators; reduce-onlycore/redTeam.ts
9CrystallizationAll gates simultaneously → insightcognition/insightCrystallizer.ts
10Theory gateInsights over coupled pairs → directional theoriescognition/theoryEngine.ts + theory daemon
11Forecast registration & scoringPre-registered claims scored against the public recordcognition/predictionRegistry.ts
12Knowledge distributionInsights and decisions back to the COGscognition/knowledgeDistribution.ts
13Proposal generationConsequential items → the decision queue, rejection-filteredcognition/proposalPipeline.ts
14Temporal decay & reasoningλ=0.002/day, floor 0.05; trajectory patternscognition/daemon.ts, core/temporalReasoning.ts
15SynthesisCross-domain pairing, deterministic seed, bridgessynthesis/daemon.ts
16WorkspaceThe integrated present moment, valence, autobiographycognition/workspace.ts
17AttentionGrants aim surplus focus at converging domains/sensescognition/attention.ts
18Entity threadsCross-domain actor tracking, receipted dailyentity senses daemon

Adaptive attention (2026-08): domain scheduling is no longer pure round-robin — a domain's effective age is multiplied when OSz's own state says it matters (recent user bridge activity, starved coverage, and converging hypotheses at ≥0.65 climbing toward the crystallization gate).


Chapter 7: The Constitutional Gates

Hard-coded, not configurable. Changing them requires code change and governance review.

Gate 1: The Confidence Birth Cap (0.70)

Every hypothesis is born ≤0.70. A new idea has no track record; certainty must be earned.

Gate 2: The Honest Clock (One Backtest Win Per Day)

A hypothesis may bank at most one backtest win per calendar day, and only against completed windows. Five wins therefore means five separate days of the world agreeing — not five queries against the same lucky window. This rule, added after the first crystallization wave, is why "≥5 backtests" means something.

Gate 3: The Crystallization Gate

All simultaneously: confidence ≥0.80 · ≥5 backtest wins on separate days · ≥3 days of age · cosine ≥0.15 from every rejection-memory entry. The 0.10 gap above the birth cap is earned headroom.

Gate 4: The Reinforcement Cap (0.95) and the Ceiling (0.99)

Evidence alone can raise a belief to 0.95. Nothing raises anything past 0.99. Certainty is never total, so listening never stops.

Gate 5: The Promotion Gate

createIntentAndProposal() → recorded human decision → decideProposal()executeProposal(). Enforced status transitions (proposal_not_pending, proposal_not_approved), receipts at every step, requireAdminToken on execution. Since 2026-08-27, human-in-the-loop integrity is itself sentinel-audited: sessions without a login flow and decisions that don't trace to a real sign-in are daily tripwires.

Gate 6: The Rejection Filter

Cosine < 0.15 from a past rejection: suppressed. < 0.30: confidence −40%. The system does not re-ask what you already answered.

Gate 7: Red Team Asymmetry

Reduce-only, structurally. A challenger that could also reward would become an optimizer.

Gate 8: Forecast Scoring Asymmetry

For theories: a correct pre-registered forecast is worth +0.03 — the only way up. A wrong one costs −15%. It takes five correct forecasts to recover one miss. Confidence bragging is mathematically unprofitable.

Gate 9: Evidence Novelty

Unchanged content counts once per window. Enforced at both observation stages. The same evidence may not reinforce a belief twice in a day.

Confidence Distribution Bands

BandRangeMeaning
Nascent<0.30Just formed, no reinforcement
Emerging0.30–0.50Early signal, needs more evidence
Developing0.50–0.65Accumulating support
Converging0.65–0.75Near birth cap, evidence converging
Approaching0.75–0.80Above birth cap, approaching the gate
Crystallized≥0.80 + gatesEarned — eligible for insight

Chapter 8: Theories, Forecasts, and the Reality Track

This chapter is new in Version 2.0, because the capability is: OSz no longer stops at insights. It explains, and its explanations are graded by the world.

From Insight to Theory

Crystallized insights are patterns that survived testing. When multiple insights couple the same domain pair, and the measured lead/lag substrate (who moves first, by how many days, at what correlation — net of the platform-wide tide) supports a direction, the theory gate composes a theory: "A leads B by N days." A theory is directional and falsifiable by construction. It is born at 0.50 — an explanation starts less trusted than the evidence underneath it, because composition adds risk.

The Forecast Contract

A theory must stake pre-registered forecasts: due-dated claims about measurable future values, registered before the fact, scored automatically when due against the public record (world senses supply the resolution data). The scorer runs hourly with a seven-day horizon sweep.

Standing

Theory-hood as durable status is not automatic. Standing is granted by a human decision — through the Promotion Gate like everything else — only after: confidence ≥0.85, a 70%+ record over at least 5 forecasts, and two weeks of survival. The machine earns the numbers; the human grants the status; the chain records both.

Reading the Track Record

The console's predictions surface shows every registered forecast with its due date, resolution, and running record. A 6–1 record means more than any confident sentence — that is the product. When evaluating anything OSz tells you, the habit is: read records before claims.

Honest Notes

Forecast resolution depends on the senses that measure outcomes; a sense outage delays scoring (it never fabricates it). And theories currently decay like all beliefs — an explanation whose forecasts stop resolving drifts down rather than lingering. Both behaviors are by design.


Part Three — Operation

Chapter 9: The Console

The console at console.oszgroup.com is the primary operating surface — a fast, installable web app (Add to Home Screen / Install works on Mac, Windows, iOS, Android; see get.html). The older React admin SPA remains available for deep administrative views, but day-to-day operation lives in the console.

Two Views

The header switches between two personas of the same system:

The Header Row

Constitution · White paper · Manual — the canon, each readable in the browser in matching format. Search — search everything OSz is. Help — glossary, playbook, connection guides, and the Documents section linking the canon. Install — the PWA prompt where available.

Ask — One Box, Everything

Ask takes plain words — weather, prices, filings, news, any domain, any question, or work orders. Deterministic routing tries verified knowledge and the tool suite first; deep answers go through the governed reasoning edge (primary model with automatic fallback — the morning sentinel probes both edges daily). Every answer cites sources; anything from OSz's own knowledge links to its evidence chain. Queries are metered at 1 Qbit (free during the founding phase, refreshed monthly).

Domains — Library and Intelligence

Every domain opens with two buttons: Library — the actual articles, in plain English, with source labels, snippets, read-in-place, and a concept search inside the domain (full-text over bodies, not just titles); Intelligence — what OSz has concluded: hypotheses, insights, bridges, confidence bands, each with an Explain affordance that renders what the finding means, how it was created, and why it matters, in plain English.

Tiles That Tell the Truth

The stat tiles are exact or honestly-labeled, never invented. Nine-digit counters auto-fit their tiles (the type shrinks; the digits never round away — "121,630,824" stays exact). The observation counter counts novel learning — after the evidence-novelty gates, re-reads of unchanged content no longer inflate it.

The Decision Queue (Governed)

Pending proposals with full provenance, one-click approve/decline with a reason, and the Decision Learning card showing each lesson land. Health sentinel reports file here; so do CI failures, agent dispatch requests, tool authorizations, and self-improvement proposals. This queue is where the operator's attention lives, so everything that needs attention is delivered to it.

Tools — the World, Under the Constitution

The tools panel lists the 42 built-in tools as clickable pills, plus the tool universe: search and browse the indexed MCP tool catalog, see which servers are open versus credentialed, authorize credentials into the encrypted vault, and watch tool offers appear inside task flows. Disclosure tools run on click; action tools generate proposals. (Chapter 15.)

Verification, In Public

Verify the chain — the console re-derives recent receipt hashes live, on demand, in front of the user (/api/console/chain-verify). The witness endpoint/api/console/chain-head returns the current chain-head hashes so anyone can record them and become an independent witness. Predictions — the public forecast track record. The tour page (tour.html) does all of this for visitors with live production numbers.


Chapter 10: The Proposal Review Workflow

The workflow from Version 1.0 is unchanged in structure — arrive at the queue, expand the evidence, decide with a reason, watch the system learn — and remains the constitutional heart of operation. Current notes:

What Arrives in the Queue Now

Intent familyWhat it asks
osz.insight.crystallizedConfirm earned knowledge
osz.synthesis.testable / bridge eventsConfirm a cross-domain connection is worth investigation
Theory standingGrant durable theory-hood to a proven explanation
osz.agent_dispatch.proposalApprove an ephemeral agent burst (Qbitz-budgeted)
Tool authorization / connectionApprove a credentialed tool server or an action-class tool use
osz.buildz.self_improvementApprove machine-authored code changes (double-gated: proposal, then code review). The first such patch passed a human gate and runs in production (df548663).
osz.health.daily_reportAcknowledge the sentinel's findings — each names its investigation path
CI failure reportsA failing build delivered as a decision, not a buried log

How to Decide

Read the evidence chain, check the record (backtests, forecast records, red-team survivals), decide with a reason — the reason is taught back. When in doubt, decline: it costs a recoverable −15%; a wrong acceptance distorts permanent knowledge. Approvals and declines are both receipted with your verified session — decisions that don't trace to a real human sign-in are a daily sentinel tripwire.

Deciding Is a Signed Act

Since the 2026-08-26 hardening: proposal decisions carry channel provenance bound to a login-created session. There is no scriptable side door; a decision recorded any other way is a breach signal the sentinel reports the next morning.


Chapter 11: The Audit Chain and External Anchors

OSz's answer to "how do you know what the system did?" is mathematics, and since August 31, 2026, the mathematics is checkable by people who do not trust us.

Two Tiers of Receipts

Chain receipts — human-consequence actions (proposals, decisions, executions, connections, grants): one hash-linked receipt per action, appended directly to osz_governance_receipts. Each receipt commits to its parent: hash = sha256(prev_hash + "\n" + canonical(body)).

Telemetry leaves — machine telemetry at cognitive volume (~96% of receipt traffic: observation records, Stage-2 analyses, contentions, synthesis pairs, red-team findings, query metering): individually provable leaves in osz_telemetry_receipts, sealed each minute in Merkle batches under one chain root. Every leaf stays provable against its chained root; the chain stays human-scale.

Contiguity by Construction

Sequence numbers are derived inside the append transaction under an advisory lock (last.seq + 1) — an aborted transaction releases its number, so gaps cannot form. Before 2026-08-31 seq came from a non-transactional Postgres sequence, and rolled-back transactions burned 47,588 numbers across 720 gaps. Those historical gaps are sealed: enumerated in osz_chain_gap_reconciliation with per-gap link proofs (all 720 prev-hash links hold — deletion is excluded by the chain itself), the ledger's digest committed to by receipt seq 5,782,399 inside the chain. Postgres-level BEFORE INSERT triggers on both chains refuse any non-contiguous number outright — a numbering defect now halts loudly instead of drifting silently. (Restore runbook: migration 0090 --rollback → restore → re-run 0090.)

Verification

External Anchors — Proof Against Rewrites

A chain held entirely in one database proves internal consistency, not originality: an actor with full write access could rewrite the entire suffix consistently. So the heads leave the building:

scripts/ops/verifyAnchors.ts replays every anchor against the live chain; a divergence is not just detected but time-bounded to the hour. The sentinel checks anchor freshness daily.

The Guard Stack, Summarized

Impossible to create (transactional seq) → impossible to accept (database triggers, self-tested live) → impossible to hide (daily sentinel patrol: gaps, orphans, ledger digest) → impossible to reintroduce (CI static guard fails any build that brings nextval near a chain table) → impossible to rewrite unnoticed (external anchors + public witnesses).


Chapter 12: Day-to-Day Operations

Production runs on DigitalOcean: an application droplet (Ubuntu, 4 vCPU / 8 GB) and a managed PostgreSQL 18 cluster (6 vCPU / 32 GB, with pgvector), plus a Spaces bucket for the permanent archive. The web surface is served by Caddy from the built SPA; the API and every daemon run in one systemd service.

The Services

systemctl status osz-api        # API + all cognitive daemons
systemctl status osz-search     # search proxy
journalctl -u osz-api --since "1 hour ago" --no-pager | tail -50
systemctl restart osz-api       # safe: the unit kills only its own stale process

Everything cognitive — ingestion, COGs, cognition, red team, synthesis, embedding worker, centroid, telemetry batcher, retention, rates refresher, prediction scorer, health sentinel, chain anchor, theory daemon, senses — starts with the service. There is no separate daemon fleet to manage.

The Morning Routine

  1. Open the console (Governed view). The sentinel has already done a structured pass at 06:00 UTC — if anything tripped, the report is in your queue with each finding's investigation path. Silence means every check passed.
  2. Work the decision queue with reasons.
  3. Glance at the flywheel tiles — intake, backtests, insights, forecasts due.

Retention and the Archive — Nothing Is Ever Destroyed

Deploys

Backups and Recovery

The managed cluster provides automated backups and point-in-time recovery; scripts/ops/backupDatabase.sh covers scheduled dumps. The irreplaceable tables are the two chains, the reconciliation ledger, hypotheses with their confidence history, insights, theories, forecasts, and decisions. Before restoring the chain tables, read the runbook in migration 0090 (drop the contiguity triggers, restore, re-create).

Environment Variables (Selected)

VariableProduction valuePurpose
OSZ_OBS_DEDUP_WINDOW_MS86400000Evidence-novelty window (24h), both stages
OSZ_RETENTION_KEEP_OBS_DAYS40Hot-store observation window
OSZ_COGNITION_INTERVAL_MS300000Cognitive cycle cadence
OSZ_HEALTH_REPORT_UTC_HOUR6Sentinel report hour
OSZ_ANCHOR_EMAIL / EMAIL_FROMoperator-setDaily anchor email (requires a verified SendGrid sender)
SPACES_*set at deployArchive + anchors bucket

When Something Looks Wrong

Start from the sentinel's report — it names the check and the path. Then: journalctl for the tagged subsystem (chainAnchor, healthSentinel, retention, cogs, osz), the console's chain-verify for integrity questions, and the verification scripts for anything constitutional. The diagnostic SQL recipes from Version 1.0 (stuck hypotheses, queue growth, contention patterns, red-team distribution) remain valid.


Part Four — For Developers

Chapter 13: The Technology Stack

The Constraints That Define the Codebase

TypeScript only — no Python, no shell-as-logic. Drizzle ORM exclusively. One PostgreSQL database (18, managed) with pgvector — no Redis, no Kafka. Structured logging only. Every catch block logs or re-throws. canonicalStringify for every hash of structured data — never JSON.stringify. Zero tsc --noEmit errors, always. Static imports only. Idempotency keys on every protocol proposal submission.

PostgreSQL 18 + pgvector

The single source of truth. Key facts as of August 31, 2026:

StoreScaleNotes
osz_cog_observations~121M rows (40-day window)Novel-only since the evidence gates
osz_embeddings~97M vectors768-dim; the biggest table (~71% of the database)
osz_governance_receipts5.7M+, verified end-to-endTwo-tier with telemetry leaves
osz_telemetry_receiptsMerkle-sealed leaves~30-day retention after sealing
osz_domainsexactly 1,000Enforced at boot

Vectors: 768 dimensions, all meaningful — dims 0–63 encode the structural profile (observation-type distribution, confidence patterns, activity, decision patterns); dims 64–767 carry lexical features (feature-hashed, rank-weighted terms). The ANN index is HNSW over half-precision (halfvec) expression — half the memory, effectively identical ranking, which is what lets the working set live in the cluster's cache. Model: osz-structural-v1, computed internally. Zero external embedding calls, ever.

LLM Surfaces (Governed Edges Only)

SurfacePurposeNotes
Ask reasoning edgeDeep answer phrasingPrimary + automatic fallback model; both probed daily by the sentinel; every call receipted and metered
Buildz gatewayProposal-gated code generationDouble-gated (proposal, then human code review)
Markus voiceReal-time voiceHuman-facing only

Zero LLM calls exist inside cognition, hypotheses, backtests, theories, or learning. The console shows the live external-call count next to the observation count; the ratio is the argument.

Repository Shape

services/api/src/osz/
  cogs/        observers, debate, Stage-2 analysis
  cognition/   the engine: hypotheses, backtests, crystallizer,
               theory engine, predictions, workspace, attention
  semantic/    embedding worker, centroid daemon, vector queries
  ingestion/   source diet, politeness gates, circuit breakers
  synthesis/   cross-domain pairing
  capabilities/ built-in tools, MCP discovery, auto-connect, resolver
  protocols/   MCP · A2A · ACP servers + task feed + governance
  core/        governanceSpine, telemetryBatcher, governedExecute,
               auditChain, canonicalJson, hash, redTeam, spacesArchive
  ops/         healthSentinel, chainAnchor, retention, dashboards
  db/          oszRepo — the Promotion Gate's enforcement
  qbitz/ tax/ bridge/ buildz/ …
apps/web/      console.html + the React SPA + landing/tour/get
scripts/       migrations (append-only history), ops (verifyChain,
               verifyAnchors, deployWeb, backups)
tools/osz/hardening/  CI guards: chain verifiers, static scans

The Hardening Suite

npm run verify = tests + static guards. npm run osz:hardening:all runs the full pass: cognition-boundary static scan (no admin symbols in cognitive paths), chain-sequence static guard (no nextval near a chain table; the appenders keep their transactional derivation), both chain verifiers (chunked, scale-proof, non-vacuous), semantic replay, boundary tests, COG neutrality, Dorothy drift safety, red-team silent-optimizer checks, and COGs cost verification. Artifacts land in artifacts/hardening/.


Chapter 14: Capabilities

What OSz can do today, with production evidence. Figures dated August 31, 2026.

Continuous Multi-Domain Observation

1,000 domains, 28 sources, dozens of world senses. ~121M observations in the live window; novel-only counting since the evidence gates (roughly 1M genuinely-new observations per day at current diet). Verify: the console's tiles, or SELECT count(*) FROM osz_cog_observations.

Honest Hypothesis Lifecycle

~8,000 active hypotheses across an eight-kind ontology; every one entitled to its daily backtest (~23,000 slots/day); saturation converts duplicate conceptions into reinforcements. Confidence: born ≤0.70, evidence-capped 0.95, ceiling 0.99, decay λ=0.002/day.

Crystallized Insight, at Scale

Thousands of insights, each carrying its complete evidence chain; the console's insight curve shows the cumulative climb with the current rate. Crystallization is not rare anymore — it is the system's steady product. What remains rare, by design, is standing for theories.

Theories with Public Records

Directional explanations composed from insights, staking pre-registered forecasts scored against the public record (+0.03 / −15%), with standing granted only by human decision after a proven record. The track record is public on the console.

The Tools Universe

42 built-in keyless tools; 93,389 tools indexed across 4,528 live MCP servers (measured at the August discovery sweep); governed auto-connect for open servers; an encrypted credential vault (AES-256-GCM) for the rest; deterministic tool resolution inside task flows; disclosure/action risk classes with the Promotion Gate on every action. (Chapter 15.)

Ask

One box over everything: verified knowledge, tools, domain intelligence, and a governed reasoning edge with automatic failover — probed daily, receipted always, metered at 1 Qbit.

Verifiable Governance

5.7M+ chain receipts verified end-to-end; sealed historical gap ledger; contiguity enforced by the database itself; hourly external anchors; a public witness endpoint; a daily sentinel patrol. Anyone with read access can reach the same conclusion without trusting us — that is the design goal, achieved.

Self-Improvement, Constitutionally

OSz observes its own behavior, proposes patches through the gate, and — after human approval at both the proposal and code-review steps — runs machine-authored code in production (first: df548663). The funnel (observed → attempted → awaiting → approved/declined) renders on the console.

Protocol Surfaces

MCP, A2A (with /.well-known discovery), and ACP servers, plus a governed agent task feed: external agents can read verified knowledge, discover tools, and propose work — and nothing they propose executes without a human. Idempotency keys required everywhere.

The Sentinel

Daily self-diagnosis against trailing baselines across intake, testing coverage, cycle health, storage, integrity, and its own anchors — filed to the decision queue. The system that audits everything audits itself on schedule.


Chapter 15: Tools and the Agent Ecosystem

New in Version 2.0: OSz knows what the world's tools are, and can reach them under the constitution.

The Built-in Suite (42)

Keyless, verified end-to-end, wired to plain-language routing with deterministic renderers: weather and marine conditions, market data and SEC filings, economic series, earthquakes and space weather, flights, scholarly papers (with fallback), clinical trials and drug labels, case law and regulations, books, structured knowledge, universities, media, recipes and food data, translation, unit conversion, calculation, geospatial routing, and more. Each is a clickable pill on the console and a routable capability inside Ask.

The Discovered Universe

The MCP discovery daemon walks the public server catalog with genuine protocol handshakes and indexes what it finds: 93,389 tools across 4,528 live servers at the August sweep, deduplicated by tool name, each with its schema, its server count, and its probe status. The catalog is listed and searchable on the console — not just searchable: agents and task flows resolve against it deterministically, so a task can discover the tool it needs.

Connection Classes

Risk Classes and the Gate

Disclosure tools (read-only: fetch, look up, compute) execute directly and are receipted. Action tools (anything that changes the world) generate a proposal — the tool call is described, queued, and executes only after human approval. This classification is enforced at both the console path and the agent path; the constitutional bug class where a tool bypasses the gate is tested against.

Agents

Article VI stands: zero standing agents. Agent work happens in approved bursts — dispatched through a proposal, Qbitz-budgeted, receipted, terminated on completion. External agents connect through the protocol surfaces and live under the same gate. The console's agent panel shows registered credentials, currently-connected agents, tasks awaiting pull — and a permanent "Standing agents: 0 — always."


Chapter 16: Extending OSz

The extension recipes from Version 1.0 remain correct: adding observation types, adding a fifth COG, adding domains (count invariant enforced at boot), adding hypothesis kinds, adding ingestion sources (politeness gates required), adding tax intents, MetaMods, and the event bus. Current additions:

Adding a Built-in Tool

Register in capabilities/capabilityService.ts with its renderer and risk class; add routing vocabulary; disclosure tools become Ask-reachable immediately, action tools inherit the proposal path. Verify end-to-end before listing — a tool that cannot answer is removed, not excused.

Adding a World Sense

Register the series with its fetch cadence and units; senses feed forecast resolution, so accuracy and provenance matter more than coverage.

Adding a Source

Give it a politeness gate honoring the source's published limits, a circuit breaker, and full provenance. One banned crawler must never silence the rest.

The Rules That Do Not Bend

No LLM calls inside cognition. No execute() in the cognitive layer. No receipt-less mutations. No nextval near a chain table (CI enforces). No silent catches. No JSON.stringify in hashes. Every extension passes npm run verify and the hardening suite before it ships.


Part Five — Context

Chapter 17: How OSz Differs

The comparison tables in Version 1.0 (versus LLMs, agent frameworks, BI, knowledge graphs, RAG) remain accurate in structure. What sharpened since:

Versus LLMs: the labs' route to capability is bigger models; OSz's is accumulated governed experience. An LLM's confidence is a tone of voice; OSz's is a number with a public win–loss record attached. An LLM can be asked to explain itself; OSz cannot avoid explaining itself — the receipts exist before the question does.

Versus agent platforms: everyone now ships agents that act; OSz ships agents that cannot act ungoverned, and makes that property independently verifiable rather than asserted.

The honest assessment stands: OSz is not a general-purpose tool. It is continuous governed cognition. Its moat is time-density — a million receipts of human judgment, forecast records that only accumulate in real time, and a chain whose length itself is evidence. And its known limitations remain real: the human bottleneck at the gate (by design), keyword-based Stage-1 perception, ordinal-not-cardinal confidence for hypotheses (theories' forecast records are the calibrated exception), and single-operator governance (multi-admin exists; quorum decisions do not yet).

Chapter 18: Benefits

For operators: a system that reads a thousand domains so you don't have to, tells you only what it can prove, files its own health reports, and gets measurably better with every reasoned decision you make.

For developers: deterministic debugging (every belief traces to rows), constitutional constraints that remove ambiguity, a hardening suite that catches violations before production, and zero-cost cognitive cycles.

For decision-makers and investors: a defensible moat of accumulated governed cognition; trustworthy-by-construction rather than contained-by-policy; verification you can hand to a skeptic ("don't trust us — check"); and clear, queryable metrics — insight curve, forecast records, approval rates, chain length — all receipted.

Chapter 19: Roadmap

Running Now (evidence on the console)

Everything in Chapter 14 — the full pipeline through theories and forecasts, the tools universe, the verification stack, the sentinel, self-improvement, protocol surfaces, the archive.

Wired, Awaiting Operator Action

ItemNeeds
Daily anchor emailA verified SendGrid sender (EMAIL_FROM) — the Spaces anchors and witness endpoint run regardless
Credentialed tool expansionOperator keys into the vault for the ranked top-100

Designed, Not Yet Built

ItemNotes
Quorum governanceMultiple reviewers with quorum decisions (multi-admin exists today)
Federated OSz instancesA2A insight sharing across sovereign instances
Receipt archiving spliceChain segments to cold storage with checkpointed verification — designed, unneeded for years at current volume
Alternative reasoning-edge routingRegional/provider failover beyond the current primary+fallback pair
OAuth-flow MCP connectionsBrowser-redirect credential grants for OAuth-only servers

Direction

Deeper senses, faster honest crystallization (never faster gates), theories that compound into bodies of explanation, and an agent ecosystem that treats the Promotion Gate not as friction but as the feature that makes delegation safe.


Part Six — The Governed Economy

Chapter 20: The Qbitz Economy — Markets, Credit, and Reserves

Added September 2026. Qbitz are OSz's unit of account: one Qbit equals one cent, always held as integer cents, never a floating value. Everything in this chapter runs through the same Promotion Gate as every other action — no Qbitz move without a human approval, and every movement writes a receipt to the audit chain. This is the constitution applied to money.

The Three Tiers of Qbitz

Every balance is made of three kinds of Qbitz, and the ledger keeps them strictly separate:

A database trigger enforces the spend order inside the engine itself: granted burns first, purchased burns last, earned is the durable remainder. So the perishable stipend is always spent before durable Qbitz, and the redeemable balance can never exceed what was actually bought. When the paid era begins, the free stipend ends and Qbitz are purchased instead — any amount you want, more or less than 2,500, at a cent each.

The Marketplace (Build & Earn tab)

A public board carries offers and wants. A listing is only an advertisement — posting one moves nothing. Taking a listing mints a dual-gate trade: two owner-scoped proposals, one for each human. The Qbitz move only in the execution where the second approval lands — atomically, with a settlement receipt. A denial, an expiry, or insufficient funds at settlement voids the trade, and nothing moves on either side. No value changes hands without both signatures.

Redemption and the Reserve

Only purchased Qbitz redeem, and only to the original payment method — granted and earned Qbitz stay in OSz. Because the chain proves what OSz owes but cannot see a bank balance, a segregated-cash reserve ledger records the dollars actually held, and a daily attestation writes the comparison onto the governance chain. The rule: the sum of purchased Qbitz outstanding is the reserve requirement, to the penny, and the recorded reserve must cover it. Supply and coverage are published at /api/console/qbitz-supply for anyone to record. A shortfall is a high-severity sentinel alarm. In the free phase the attestation runs honestly at requirement $0.00, covered.

Where you manage it: Governance → Operations → the Reserve card. Admins record deposits, yield, withdrawals, and adjustments (bank reference and note required, receipted); the loan book sits beside it.

Agents Improving OSz — For a Bounty

Connected agents can propose changes to OSz itself, through every protocol surface (MCP propose_improvement, ACP improvement_proposal, A2A propose_improvement) — gated by a human admin exactly like every other proposal. The agent's key is owner-bound, so an accepted improvement credits the owner an earned-Qbitz bounty. The same handler pays the My OSz suggestion tile and the developer change-proposal path identically: humans and agents earn on the same terms for improving the system they share.

The Loan Program — Financed Qbitz

A borrower receives Qbitz now for a flat transaction fee paid at origination; the price of the Qbitz is billed at term (30 days) on a card mandate the borrower consents to when approving — the approval is the signature. An originator who backs a peer's loan is closed out at execution, every time: their stake returns in the same transaction, plus their origination share — riskless by construction. OSz is cash-positive from the moment of origination, so there is no loss state and no loan reserve. The program ships dark — the machinery is live and proven, and origination opens the instant charging goes live (the console shows the honest "opens with the paid era" message until then). Loan disbursements are the one grant that continues into the paid era.

Every capability in this chapter is learning-side value creation with a human signature on every consequence and a receipt behind every movement. An agentic economy that is governed, auditable, and human-gated end to end is the only kind an enterprise, a regulator, or a court can accept.

Appendices

Appendix A: Quick Reference Card

Constitutional Gate Values

GateValue
Hypothesis birth cap0.70
Reinforcement cap (evidence alone)0.95
Absolute confidence ceiling0.99
Crystallization≥0.80 · ≥5 backtest wins on separate days · ≥3 days · ≥0.15 cosine from rejections
Backtest clockOne win per hypothesis per calendar day, completed windows only
Theory birth0.50
Forecast scoringCorrect +0.03 (only way up) · Wrong −15%
Theory standing≥0.85 conf · 70%+ over ≥5 forecasts · 2 weeks · human grant
Rejection filter<0.15 suppress · <0.30 −40%
Decision teachingDecline −15% (rejection memory) · Approve reinforces + distributes
Temporal decayλ=0.002/day, floor 0.05
Red teamReduce only
Evidence novelty window24h (OSZ_OBS_DEDUP_WINDOW_MS), both observation stages
Attention grants≤12 active
Qbit$0.01, integer cents; queries 1 Qbit (founding phase: free)
Settlement gate$1,000 (100,000 cents)

Verification Commands

# Full chain verification (5.7M receipts, ~15-30 min)
DATABASE_URL=... npx tsx scripts/ops/verifyChain.ts --all
# Fast recent-window check
DATABASE_URL=... npx tsx scripts/ops/verifyChain.ts
# External anchors vs. live chain
npx tsx scripts/ops/verifyAnchors.ts
# Contiguity triggers status / live selftest
npx tsx scripts/migrations/0090_chain_contiguity_triggers.ts --status
npx tsx scripts/migrations/0090_chain_contiguity_triggers.ts --selftest
# CI hardening suite
npm run verify && npm run osz:hardening:all
# TypeScript (must be zero errors)
cd services/api && ../../node_modules/.bin/tsc --noEmit

Production Operations

systemctl status osz-api && journalctl -u osz-api -n 50 --no-pager
./scripts/ops/deployWeb.sh          # web deploy with SW cache-bust
npx tsx scripts/migrations/00NN_*.ts --dry-run   # always dry-run first

Key Paths (Additions Since v1)

PurposePath
Governance spine (two-tier receipts)services/api/src/osz/core/governanceSpine.ts
Telemetry batcher (Merkle sealing)services/api/src/osz/core/telemetryBatcher.ts
Chain anchorsservices/api/src/osz/ops/chainAnchor.ts
Health sentinelservices/api/src/osz/ops/healthSentinel.ts
Retention + archiveservices/api/src/osz/ops/retention.ts, core/spacesArchive.ts
Theory engine / predictionsservices/api/src/osz/cognition/theoryEngine.ts, predictionRegistry.ts
Workspace (present moments)services/api/src/osz/cognition/workspace.ts
Attentionservices/api/src/osz/cognition/attention.ts
Capabilities (built-in tools)services/api/src/osz/capabilities/capabilityService.ts
MCP discovery / auto-connect / resolverservices/api/src/osz/capabilities/mcpDiscovery.ts, autoConnect.ts, toolResolver.ts
Stage-2 analysis (novelty-gated)services/api/src/osz/cogs/cogAnalysis.ts
Console (server)services/api/src/routes/consoleStats.ts, consoleOps.ts
Console (page)apps/web/public/console.html
Hardening guardstools/osz/hardening/

URLs (Production)

SurfaceURL
Consolehttps://console.oszgroup.com/console.html
Live tourhttps://console.oszgroup.com/tour.html
Installhttps://console.oszgroup.com/get.html
Witness endpointhttps://console.oszgroup.com/api/console/chain-head
Live chain verifyhttps://console.oszgroup.com/api/console/chain-verify
Documents/docs/OSZ_Constitution_v2_0.html · /docs/OSz_White_Paper_V4_8.html · /docs/OSz_Operator_Manual_v2.html

Appendix B: Constitutional Excerpts

The excerpts from Version 1.0 remain in force verbatim: Article I (Separation of Learning and Authority), Article II (The Promotion Gate), Article VI (No Standing Agents), the Four-COG rule, the governance receipt requirement, transaction atomicity, the silent-catch ban, hash determinism, and the confidence constitution. Version 2.0 adds their operational descendants:

The Two-Tier Receipt Rule

Machine-telemetry action types are Merkle-sealed leaves under chained roots; human-consequence receipts append directly to the chain, one per action, always. No human action is ever batched.

The Contiguity Rule

Chain sequence numbers are derived inside the append transaction, and the database refuses any non-contiguous receipt. Historical gaps exist only inside the sealed, chain-committed reconciliation ledger. An unexplained gap fails verification.

The Anchor Rule

The chain's heads are written hourly to storage the database's credentials cannot rewrite, and exposed publicly as hashes for independent witnesses. A history that diverges from an anchored head is a rewrite, time-bounded to the anchoring interval.

The Evidence-Novelty Rule

An observation identical to one recorded within the suppression window is a repeat, not evidence — no row, no leaf, no embedding, at every observation stage. Only change is signal.

The Honest-Clock Rule

One backtest win per hypothesis per calendar day, against completed windows only. The evidence window is never shortened. Certainty is earned on the calendar, not in the loop.

The Human-Decision Provenance Rule

Every proposal decision carries channel provenance tracing to a login-created human session. Decisions minted any other way are breach signals, and the sentinel reports them the next morning.

OSz Group · console.oszgroup.com · Operator's Manual v2.1 · September 2026
This manual is honest by rule: every figure carries its measurement date, and the live system will always show you the current number — with a receipt.


OSz Group · console.oszgroup.com — this document renders from the canonical source in the OSz repository.