An operative system is an organization you can install.
Models think. Agents act. Connectors attach. What was missing is the structure that holds those pieces on one mission. You install the method. The instance is the organization that follows you.
01 Definition
A complete system for one mission, compiled as one package.
Definition
Not a prompt. Not a chatbot. Not a single agent with a persona.
An OS combines everything required to operate a domain and runs as one system: Directors, NanoTeams, Agents, Skills, Workflows, Data, Memory, Knowledge, Tools, Automations, Interfaces, Permissions, Evaluations.
A mission is a bounded job. The OS is the organization that can run that job end to end. It understands the request, assigns the work, loads the method, uses the tools you authorized, writes the objects, stops at a gate when the contract says so, and remembers what mattered. A chat can imitate that for one sitting. It cannot hold it as a standing system.
The package is the official formula: sealed, versioned, checked as a composition. The instance is what you actually run. Context, goals, rules, overlay, objects, memory, connections, and permissions belong to the instance. Two people can install the same OS and build two different organizations. The same OS. Never the same organization.
One mission. An entire intelligence system.
Scale follows the mission. A small OS can be a Director and a short set of agents. A large one can hold many NanoTeams, nano directors, and long workflows. You do not start from a generic chatbot and bolt structure on later. You start from the job, then the system that can hold it.
02 Orchestration
The Director holds the OS. A nano director holds a specialty. Agents do the work.
Orchestration is why an OS is not a pile of chats. Someone has to decide what the job is, who moves, which method loads, and when the work should stop. That seat is the Director. You talk to it first. You do not spray the same prompt at every agent and hope the organization appears.
The Director understands the objective, clarifies the unknowns, proposes a plan, mobilizes responsibilities, and synthesizes the result. It can defer, refuse, ask for proof, offer a variant, or stop cleanly. It cannot grant itself a permission because the model thought the permission would be useful. The kernel still checks the plan, the rights, the budget, and the transitions.
A NanoTeam is a specialty, not a personality. Research, inversion, allocation, critique: each team exists because that lens must stay independent. A nano director sits on that team. It holds the specialty's mission the way the root Director holds the OS. The compiler reads that seat from the team graph (director, nano_director, or the team owner) and pins it as the team's root. Sub-teams, replacement, and evolution keep stable ids so references do not break.
Agents sit inside those teams. An agent id is a compiled seat with a job, skills, tools, prohibitions, and an intelligence need. teamId is that seat. Guessing names fails. list_agents is how you see the roster. A tone or editorial profile never changes permissions. Output is a result, a short justification, useful sources, and uncertainty, not a dump of private model reasoning.
Independence is compiled, not hoped. A review presented as independent gets a frozen brief, shared sources, and a context that does not see the other drafts first. A variant in the same context is labeled as a variant. Isolated seats can still share the bias of the same model. The OS does not pretend otherwise.
Intelligence is assigned by need, not by pasting a model name into the package. Director, code, review, write, research, extract, classify, fast, vision. One catalog resolves the need to the best model the current host can run. A classifier should not wake a flagship seat. A Director should not share a cheap extract model. The host still pays. Agentik does not take that invoice.
This is the technological step after agents. An agent can act. An OS can organize action: named roles, a method, a record, and a gate. The advance is not a smarter reply. It is a standing organization that can be installed, inspected, and resumed.
03 Workflows
A workflow is a versioned graph. An automation is that graph in time.
Workflows are the repeatable route through the organization. Frame, then research, then isolated analyses, then inversion, then a memo, then a human gate. The graph is compiled. Each step names a role, inputs, dependencies, outputs, allowed context, rights, effects, budget, timeout, retry, validation, and escalation. Isolated seats do not see each other's drafts first. That is the point. A custom GPT collapses those lenses into one voice.
The chain is request, mission, plan, jobs, attempts, results, evaluations, objects, events. There is no separate workflow chat tool. A run starts through the Director, or through run_os with an intent. ask_director and ask_team open the same kind of envelope: a blocked host job. Nothing on the host runs until approve. Reset and wake wait there too. Host LLM jobs stay NOT_RUN. Agentik does not silently call a cloud model.
Skills, programs, tools, and capabilities are not the same object. A skill is a reusable method (pre-mortem, customer interview, brief). A program is deterministic code with a contract and tests (margin, validation, transform). A tool is authorized access to an outside action. A capability is a typed business result the OS can expose to another OS (prepare a decision, produce an editorial plan). Inter-OS composition travels through capabilities. It never implies access to another OS memory, secrets, or premium methods.
An automation adds a trigger, conditions, and an operations policy to a workflow: a date, a recurrence, an event, a webhook. Triggers shipped in a package stay off, or wait for explicit onboarding. Installing a Content OS does not start publishing on an external account. A host that is offline can leave an occurrence waiting. The scheduler does not invent a live model or a right to use your accounts. After several days away, catch-up is a policy, not a flood of jobs.
Evaluations say whether the work was good enough to keep. Permissions say who may act. Resume respects workflow version, input hashes, and rights. It does not blindly replay an external effect. After an ambiguous failure, effect_unknown means check the effect, not run it again. The gate is not decoration. It is how an OS stays an organization instead of becoming an unsupervised script.
04 Memory
Objects, memory, and overlay live on the instance. The laptop does not hold the OS.
Data is the objects the OS keeps: a decision, a brief, an experiment, a risk. Memory is what should persist after the run. Knowledge is the method that should not live only in someone's head. You reopen an instance. You do not rebuild the organization from the last thread.
Install creates a row in a fixed schema. It does not mutate a new Convex table per OS. Overlay is private. What the package marks as cannotOverride stays in force. Three resets exist: memory, structure, full. They wait on approve. Export, then wipe. No ghost copy.
Every official OS and each agent declare five living surfaces: Instructions, Memories, Skills, Routines, Integrations. Routines are declared. They run on the host after approve. They are not an always-on meter. Skills are methods the seat already knows. You do not re-explain the craft every morning.
$99 and $199 hold memory, overlay, and resets. A lifetime unlock opens the OS. It does not create a cloud store. Change host later. The instance stays on Agentik. The host is the mouthpiece.
05 Control
MCP is I/O. Connections attach when a run needs them. The OS owns the job.
You stay in the host you already pay: Claude, Cursor, ChatGPT, Codex, Hermes. Agentik-OS is the HTTP connector. OAuth for Cursor and other hosts. A paid API key for CLI. GET /api/mcp is public health. POST uses your session or key. The OS arrives as tools plus a Director that already knows the mission.
MCP is the control layer, not the product. The OS owns the job, the objects, and the gates. The host runs the mapped model after you approve. Unpaid accounts can finish OAuth and still receive no tools. The connector without an organization is a socket. The organization is the OS.
Ads, CRM, CMS, or a repo are not pre-wired. You attach them when a run needs them. connect_app starts a connection and returns an OAuth URL. The list you see is toolkit plus a ca_ id, not a vendor dump. list_connections is the authorized set, not a catalog of every app on earth.
A binding names provider, operation, transport, schema, scopes, account holder, sensitivity, side effect, timeout, quotas, possible cost, idempotence, errors, and last functional check. A paid media tool is not free because Agentik knows how to call it. Secrets are references to dedicated storage, never values in packages, chat, logs, or frontend files. Connect, widen scope, and revoke stay visible.
Capabilities stay provider-neutral when they can. media.generate, content.publish, documents.read can receive different certified bindings. A missing adapter is an explicit gap, not fake compatibility. CLI, API, MCP, and files have different contracts. The Builder binds the integration the run actually needs to the connection you actually authorized.
06 Contract
A folder of agents is not an OS. The compiler checks the system.
The parts are a composition, not a buffet. The compiler seals a package and checks it as a system: organization, methods, data, interfaces, execution, control, lifecycle. A prompt library is not an OS. A named folder is not a PASS. RELEASE stays BLOCKED until a distinct gate says otherwise. That honesty is part of the product.
The technological claim is narrow and real. Models already think. Agents already act. Connectors already attach. What was missing is the structure that makes those pieces work together on one mission: a Director, nano directors, a roster, a workflow, objects, memory, permissions, and a human gate, compiled once and installed on the host you already pay. That is an operative system.
One OS is useful. A stack becomes an organization. Decision can inform Content. Content can feed Growth. Those packages expose typed capabilities without collapsing into one giant agent. Later names are the shape of demand, not a ship date. If the OS does not exist, Studio on a paid monthly plan is how you design one. A lifetime unit still cannot create OS.
Argument is the case for the layer. How to talk is the operating guide after the host is connected. This page is the system itself: what you actually install when you install an OS.