Skip to content
SafetyMPPublic

About

Company-day simulation: firm model, work contracts, and PDP/PEP governance. Not an agent framework and not production SaaS.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

73 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

CorpOS

One scripted company day. Support hands a $49 refund to Finance. Finance settles billing.issue_refund through the tool gateway and hands the work to Ops. Ops queues ops.restart_service for billing-api. The refund stays on the ledger. The restart stays queued until Approve, Reject, or Kill.

POST /api/company-day runs that day. It does not settle the restart, and it does not honor autoApproveException from the JSON body. An unauthenticated caller cannot auto-approve.

CI CodeQL OpenSSF Scorecard License: Apache-2.0 Node

Jump to: Demo · Quick start · Architecture · Contributing · Security · ADRs


Demo

CorpOS ops console — agents hand off a company day (support → finance → ops), trust unlock, and Governor (synthetic demo data)

Screenshots

Ops Company day Governor
Ops Company day Governor

Click Run company day to watch the activity timeline: support → finance → ops. The refund stays in place. The service restart stays queued until Approve, Reject, or Kill.


Quick start

npm install
npm run build
npm run dev        # ops console on $PORT or 3000

Contributors and CI should use npm ci --include=dev (see CONTRIBUTING.md).

npm test
npm run scenario                 # default day exits 0: refund stays, restart stays queued
npm run audit:verify
./scripts/harness/verify.sh      # functional / static acceptance
./scripts/harness/adversarial.sh # authorized local adversarial probes (CI also runs this)

Container

docker build -t corpos .
docker run --rm -p 3000:3000 corpos

CI may publish images to ghcr.io/safetymp/corpos (tags: branch, sha, semver, latest). Optional Fly.io deploy runs from .github/workflows/deploy.yml on GitHub release when FLY_API_TOKEN is set — see fly.toml.

Architecture

Layer Package / app Responsibility
Firm / work / control @corpos/core Contracts, gateway, policy, trust, audit, company day
MCP knowledge @corpos/mcp-knowledge Real local MCP server (stdio)
API @corpos/api Hono REST + SSE
Ops console @corpos/console Vite + Preact

Stack: Node ≥22 · TypeScript · npm workspaces · Hono · Drizzle + libsql · official MCP SDK · Preact. No Express, no better-sqlite3, no agent-framework lock-in.

Architecture decisions live in docs/adr/README.md.

Security

Reference architecture — not production-hardened. DASHBOARD_API_TOKEN is required for approve/kill mutations by default; CORPOS_MODE=local does not skip the bearer gate. Decide/appeal bind the decider and tenant to DASHBOARD_OPERATOR_ID / DASHBOARD_TENANT_ID, not the request body. Set CORPOS_ALLOW_UNAUTHENTICATED=true only for local simulation. See SECURITY.md.

Community

Contributing · Code of Conduct · Security · ADRs

License

Apache-2.0 — Copyright © 2026 SafetyMP.

About

Company-day simulation: firm model, work contracts, and PDP/PEP governance. Not an agent framework and not production SaaS.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages