OctoView Labs

Topos

An agentic operating system. Computers got operating systems because programs could not be allowed to run wild on shared hardware; something had to grant permissions, schedule the work, and keep the books. Topos is that layer for AI agents. It does not make them faster or cleverer. It makes them governable, and it makes what they did provable: to an auditor, a regulator, or a court, months after the fact, without anyone having to take a person's word for it.

The problem it solves

Organisations in regulated industries are being asked to let AI agents write and change production systems. The engineering case is strong. The accountability case is missing. When a supervisory authority asks who authorised this change, what verified it, and what evidence do you hold, most AI-assisted pipelines cannot answer. Chat transcripts are not evidence. Commit messages are not authorization. A green build is not a verdict.

Topos exists so those questions have answers that survive scrutiny.

How it works

1. Named human authorization

No agent act reaches production on its own word. Every substantive change begins as a registered intent stating what is being attempted and why, in plain sentences a person can read aloud. Policy decisions such as widening a scope, overriding a limit, or approving a design carry an operator's signature as a durable record. The machine signs facts about what it did. It never signs permission to do it.

2. Independent verification

"Done" is a verdict, not a claim. The agent that performs work does not get to certify it: a separate verifier re-derives the result, and adversarial review rules on designs before they are built. Claims that cannot prove what they assert are refused at the boundary rather than corrected afterwards, and the refusal is itself recorded.

3. Tamper-evident evidence

An append-only ledger is the single source of truth. Append-only means a wrong entry can never be deleted, only superseded. A backup can be restored to hide a mistake; this ledger cannot. That is what an auditor requires, and what accountability demands. Every dashboard, report and view is derived from the ledger and can be rebuilt from it. Records are hash-chained so that alteration is detectable. Refusals, retractions and overrides stay on the record permanently. The system is architecturally required to keep its own failures, not merely permitted to.

What that looks like in practice

Three live views of the Topos substrate: activity map, codebase structure, dependency graph
The substrate observing its own agents. The banner: in one 24-hour window of our own development substrate, the doors refused 141 claims from AI agents and admitted the rest. Every refusal is on record with its reason. A system that never refuses anything is not checking. Most systems hide their losses. This one is required to confess them.
A live intent lineage graph from the Topos ledger: a parent intent in BUILD, its children in REGISTERED, BUILD and PARKED, and grandchildren in PARKED and RELEASE, with each parent-child edge labeled
The work itself runs under governance. A real lineage from the live ledger: a parent intent under build decomposed into governed children. One is mid-build, one registered and waiting, one deliberately parked by the operator's signed scope, and one released. Every box is an intent with a phase; every edge is a recorded fact; nothing on this graph happened without the ledger seeing it. This decomposition machinery is the subject of "The only tractable prediction."
Animated: the butterfly view of a live regulated workload growing through its early months, then a source file opening with the line 126 edits traced to seven named agents, agent activity marks in the gutter, and the source code blurred
Time travel, then evidence. A real regulated workload replayed from the ledger: the early months of the work grow wing by wing, then one file opens. The header line is the point: 126 edits, traced to seven named agents, with every touched line marked in the gutter. The source is blurred because it is a customer's; the provenance is ours to show, and it survives the blur. That is the product in one picture: the code is confidential, the accountability is not.

An operating system, not a tool

The parallel is exact. Agents are the processes, whichever vendor's agents you run. Human signatures are the permission layer. The append-only ledger is the record of everything. And like any kernel, Topos stays domain-blind: skillsets plug in on top. Software engineering is the first, because we needed it ourselves; financial reporting and legal work are next. Nobody asks whether an operating system competes with the programs it runs, and Topos does not compete with your agents. It is what makes running them defensible.

Where this is going

A record should not have to depend on the agent's honesty. Today every claim is checked at the boundary and refused without evidence. In research is a second, independent observation plane: kernel-level telemetry, using eBPF, that sees what a process actually did at the system-call level regardless of what it reported. Self-report and kernel observation then check each other, and when they disagree, the disagreement is the finding. Watching without asking is an operating system's natural duty, and it is where Topos goes next.

Who it is for

Institutions where an engineering decision has to be defensible to someone outside the engineering team: banking and capital markets, regulatory reporting, and legal work where the provenance of a document matters as much as its content. The common feature is not industry but obligation: somebody will eventually be asked to prove what happened.

The doctrine underneath

Topos is the mechanical form of a short set of laws we publish in full: nothing exists unless it exists in the ledger; operators sign policy acts and machines sign facts; a gate that cannot catch a planted crime is theater. Read the laws, and the questions we actually get, answered plainly.

What using it looks like

The full walk from idea to landed change, every step a recorded fact, is on the life of a change. How an institution's data is held is on security and data, and the words we use are defined in the vocabulary.

How it is delivered

An enterprise platform, self-hosted inside your perimeter or managed by us, with the full audit ledger exposed behind a typed API. It runs alongside your existing pipeline rather than replacing it. Deployment, data residency and retention are configured per institution.

Status

In production use and under active development. Engagements are currently taken on a design-partner basis so that the substrate is shaped by real regulated workloads rather than assumptions about them. Request early access.

← octoviewlabs.com · About the company