Topos
An agentic operating system. Computers got operating systems because programs could not be allowed to run wild on shared hardware; something had to grant permissions, schedule the work, and keep the books. Topos is that layer for AI agents. It does not make them faster or cleverer. It makes them governable, and it makes what they did provable: to an auditor, a regulator, or a court, months after the fact, without anyone having to take a person's word for it.
The problem it solves
Organisations in regulated industries are being asked to let AI agents write and change production systems. The engineering case is strong. The accountability case is missing. When a supervisory authority asks who authorised this change, what verified it, and what evidence do you hold, most AI-assisted pipelines cannot answer. Chat transcripts are not evidence. Commit messages are not authorization. A green build is not a verdict.
Topos exists so those questions have answers that survive scrutiny.
How it works
1. Named human authorization
No agent act reaches production on its own word. Every substantive change begins as a registered intent stating what is being attempted and why, in plain sentences a person can read aloud. Policy decisions such as widening a scope, overriding a limit, or approving a design carry an operator's signature as a durable record. The machine signs facts about what it did. It never signs permission to do it.
2. Independent verification
"Done" is a verdict, not a claim. The agent that performs work does not get to certify it: a separate verifier re-derives the result, and adversarial review rules on designs before they are built. Claims that cannot prove what they assert are refused at the boundary rather than corrected afterwards, and the refusal is itself recorded.
3. Tamper-evident evidence
An append-only ledger is the single source of truth. Append-only means a wrong entry can never be deleted, only superseded. A backup can be restored to hide a mistake; this ledger cannot. That is what an auditor requires, and what accountability demands. Every dashboard, report and view is derived from the ledger and can be rebuilt from it. Records are hash-chained so that alteration is detectable. Refusals, retractions and overrides stay on the record permanently. The system is architecturally required to keep its own failures, not merely permitted to.
What that looks like in practice
An operating system, not a tool
The parallel is exact. Agents are the processes, whichever vendor's agents you run. Human signatures are the permission layer. The append-only ledger is the record of everything. And like any kernel, Topos stays domain-blind: skillsets plug in on top. Software engineering is the first, because we needed it ourselves; financial reporting and legal work are next. Nobody asks whether an operating system competes with the programs it runs, and Topos does not compete with your agents. It is what makes running them defensible.
Where this is going
A record should not have to depend on the agent's honesty. Today every claim is checked at the boundary and refused without evidence. In research is a second, independent observation plane: kernel-level telemetry, using eBPF, that sees what a process actually did at the system-call level regardless of what it reported. Self-report and kernel observation then check each other, and when they disagree, the disagreement is the finding. Watching without asking is an operating system's natural duty, and it is where Topos goes next.
Who it is for
Institutions where an engineering decision has to be defensible to someone outside the engineering team: banking and capital markets, regulatory reporting, and legal work where the provenance of a document matters as much as its content. The common feature is not industry but obligation: somebody will eventually be asked to prove what happened.
The doctrine underneath
Topos is the mechanical form of a short set of laws we publish in full: nothing exists unless it exists in the ledger; operators sign policy acts and machines sign facts; a gate that cannot catch a planted crime is theater. Read the laws, and the questions we actually get, answered plainly.
What using it looks like
The full walk from idea to landed change, every step a recorded fact, is on the life of a change. How an institution's data is held is on security and data, and the words we use are defined in the vocabulary.
How it is delivered
An enterprise platform, self-hosted inside your perimeter or managed by us, with the full audit ledger exposed behind a typed API. It runs alongside your existing pipeline rather than replacing it. Deployment, data residency and retention are configured per institution.
Status
In production use and under active development. Engagements are currently taken on a design-partner basis so that the substrate is shaped by real regulated workloads rather than assumptions about them. Request early access.