/ How I build · 01
Every claim below points somewhere you can check it: a kill memo, a register, a file in this repo. verified 2026-08-07
/ The business side · 02
The studio makes money when a bet works, not when a sprint closes. That changes what gets built, what gets stopped, and how it is priced. These are the parts of that which are visible from outside.
/ 01
Every venture enters with a named gate, a date, and a number that would end it. Willingness to pay, market access, risk, timing. If the gate fails, the venture stops and the memo goes public.
Instead of · A roadmap tells you what to build next. It has no opinion about when to stop, which is why most things that should have died are still being funded.
/ 02
The portfolio is owned or co-owned, two of them with named partner entities that carry real obligations. Client Systems work is fixed scope against a defined operating outcome.
Instead of · An agency gets paid whether or not the thing works. That is not a character flaw, it is what the contract rewards. Ownership rewards something else.
/ 03
Fixed scope, a defined operating outcome, and a written condition that closes the engagement. The ladder from a written fit read to an install is published, including what each step costs.
Instead of · A retainer pays for presence. It quietly converts a supplier into a dependency, and the incentive to finish disappears on both sides.
/ 04
Each archive entry carries the bet, the gate that failed, the date, and the memo. Not a post-mortem written for comfort, the criterion that was set in advance and then missed.
Instead of · Every studio publishes its wins, which is why wins carry almost no information. The archive is what makes the rest of the portfolio readable.
/ 05
This site, its content CMS, the ship log, the billing gateway, and the operator dashboard are the same layers a Client Systems install puts in. The implementation files are readable, not described.
Instead of · A reference implementation a buyer can open is a different category of evidence from a deck about one.
/ The growth side · 03
Build is abundant now. Demand is not. Every venture and every install carries the machinery that gets it in front of someone, measured well enough to know whether it worked.
/ 01
A loop has to clear five criteria before it gets budget: the output has to feed the input, the cycle has to be measurable, and it has to survive without new spend. Funnels stay, but as diagnosis rather than strategy.
Instead of · A funnel is a report on what already happened. A loop is an asset that produces the next cohort. They are priced identically and they are not the same thing.
/ 02
Channel work runs single threaded until payback is visible by cohort, then it gets written into a playbook the client's own team runs. Only then does a second channel start.
Instead of · Running four channels at once produces activity in all four and attribution in none. Sequencing is slower for a quarter and faster for a year.
/ 03
One North Star, a minimum instrumentation set, and cohort tracking exist before the first campaign runs. Attribution cleanup comes before attribution reporting.
Instead of · Spend that starts before measurement can never be evaluated afterwards, only defended. The number arrives too late to change the decision it was meant to inform.
/ 04
The category, the spine, and the job the buyer is actually hiring for get written before a channel plan exists. The words on the page are treated as part of the system, not decoration on it.
Instead of · A weak position makes every channel more expensive at once, and no amount of spend corrects it. It is the cheapest thing to fix and the last thing most teams touch.
/ 05
CRM scoring, routing, and lifecycle loops ship wired together, with the handover playbook as a deliverable rather than an afterthought.
Instead of · Campaigns end when the person who ran them leaves. A wired system keeps running, which is the entire difference between a marketing spend and a marketing asset.
/ Operating stack
What I actually run, and the defaults I install. Models are rented; harnesses and eval corpora are owned. Not every tool on every engagement.
Full hub: Operating stack memo →
Jobs-to-be-Done
RECONChristensen / Ulwick
Name the job a buyer hires a solution to do, the forces that block progress, and the outcomes that count as proof.
Exiid: Opportunity Engine, smoke offers, concierge specs
Receipt →Theory of Constraints
crossGoldratt
One bottleneck at a time: exploit before you elevate headcount or tooling.
Exiid: Brief Desk to first paid Diagnostic as the constraint
Receipt →Working Backwards (PR/FAQ)
RECONAmazon
Write the outcome and proof metric before scope expands.
Exiid: Model Transfer Evaluation artifacts
Receipt →Behavioral demand testing
RECONMom Test / Pretotyping lineage
Opinions are noise; costly actions are signal.
Exiid: Signal Ladder rungs 4 and 5
Receipt →Wardley Mapping
RECONSimon Wardley
Timing window and evolution of market components.
Exiid: Market Transfer criterion 5: timing window
Receipt →Shape Up
RAIDBasecamp
Fixed time, variable scope; appetite not estimate.
Exiid: 2 to 4 week Evaluation, 3 to 6 week validation sprints
Receipt →Kano Model
RAIDKano
Separate must-haves from delighters in MVP scope.
Exiid: Build stage artifact discipline
Receipt →North Star + AARRR
RAIDAmplitude / Pirate Metrics
One primary outcome metric; cohort instrumentation.
Exiid: Growth Architecture Minimum Instrumentation Set
Receipt →Growth loops
RAIDReforge-style doctrine
Loops compound; funnels diagnose.
Exiid: Loop Qualification Test (five criteria)
Receipt →ICE / RICE
RAIDSean Ellis / Intercom
Prioritize experiments when capital is scarce.
Exiid: Validation Engine kill lines
Receipt →Workflow-first automation
crossPattern
Automate steps, not an AI.
Exiid: Three lanes: deterministic, judgment-light, judgment-heavy
Receipt →Eval-driven promotion
crossML ops practice
Autonomy earned by evidence, revoked on suspicion.
Exiid: Autonomy Ladder L0 to L4, Approval Line
Receipt →OODA
crossBoyd
Fast observe, orient, decide, act cycles.
Exiid: Fast cycles, kill early operating norms
Receipt →DACI
crossIntuit
Who decides on Client Systems, Venture Partnership, and Advisory structures.
Exiid: Engagement track selection
Receipt →Brief Desk to fit review
RECON2 to 3 business days: next steps or direct no-go with reason.
Decode to Validate (RECON) or kill
crossRECON before RAID; weak evidence stops the work.
Signal Ladder gating
RECONNo build capital below rung 4 (commitment or payment).
Concierge to automation spec
RAIDManual delivery logs become Product and AI build input.
Autonomy promotion and demotion
crossEval evidence promotes; suspicion demotes instantly.
Eval loop
crossGolden set on change, runtime checks every run, weekly drift review.
Public kill archive
crossFailed gates published with written reasons.
JTBD + outcome mapping
InstallRECONJob, forces, desired outcomes for smoke offers
Similarweb / Semrush
BenchRECONReference-model traffic and channel baselines
Paid signal for corridor scans
Crunchbase / PitchBook
BenchRECONFunding, M&A, category maturity
Figma
InstallRECONOffer flows, funnel maps, exceed-delta sketches
Notion
InstallRECONResearch memos, go/no-go packages, partner data rooms
Linear
InstallRECONIssue intake, sprint scope, kill decisions as closed issues
GitHub
RunscrossSpecs, ADRs, public kill archive source
Model-agnostic where it helps. Gated everywhere it matters.
Cursor
Primary coding harness: multi-file edits, CI-gated merges
RunsClaude
Decode, drafts, go/no-go memos, reviewed automation
RunsCodex
Bench coding + failover when Anthropic unavailable
BenchGemini
Bench for long-context research and multimodal decode
BenchOpenCode
CLI agent surface for headless CI and scripted lanes
InstallOpenClaw
Heartbeat agents for always-on ops on client installs
InstallPi
Lightweight L1 assist for quick capture workflows
BenchHermes
High-reasoning strategy and CEO-class planning tasks
BenchAlso fluent across these runtimes
Build and install work is not locked to one agent runtime.
Logos identify tools we use or install; no endorsement implied.
Models are rented. Route by task lane, not one model for everything.
| Task | Default | Autonomy |
|---|---|---|
| Decode / research | Claude SonnetBench: GPT-4o, Gemini Pro | L1 |
| Structured extraction | Claude Haiku / GPT-4o miniBench: Gemini Flash | L2 |
| Code generation | Claude Sonnet via Cursor | L2 |
| High-stakes draft | Claude SonnetBench: Opus for hard judgment | L2 |
| Irreversible / identity-bearing | Human only | L0 |
| Embeddings / RAG | text-embedding-3-large or voyage-3Bench: Cohere embed | L4 |
| Batch enrichment | Haiku / mini at volume | L3 |
Coding harness
RunsAgent edits + typecheck + lint + unit/E2E CI before merge
Gates: CI green · Playwright on conversion paths
Receipt →Eval harness
InstallGolden set on every prompt/model change; trace comparison
Gates: 50 golden cases minimum
Receipt →Orchestration harness
InstallDurable workflows, retries, human approval nodes
Gates: n8n · Temporal · Paperclip (bench)
Receipt →Promotion harness
InstallAutonomy Ladder gates: 200 @ 98% before L3; demotion on suspicion
Gates: 200 reviewed @ 98%
Receipt →/ The build · 05
Four of them read every pull request before it can merge, and none of them can approve it. What actually blocks a merge is enforced by a server rather than by a habit, and the controls I have not switched on are listed too, with the reason.
This describes exiid-os, the repo behind this site. It is the same posture I install, not a claim about a system you already run.
Edit
On my machine, with the agents denied every env file and key.
Pull request
Direct pushes to main are refused by the server, not by habit.
Agent review
Four reviewers read the diff automatically. Advisory: none can block or approve.
Typecheck · tests
A type check, the full suite, and a build that runs with no secrets.
Size budget
485 KB gz of first-load JavaScript per route, or the build fails.
Branch protection
Required check, admins included, no force push, no deletion.
Production
Deploys on merge to main. Nothing reaches here another way.
There is no second path. Direct pushes to main are refused by GitHub, and that applies to the account that owns the repo.
/ Before anything ships · 06
I cannot merge past my own check.
Every pull request runs a type check, the full test suite, and a production build.
The build fails if a page gets heavier.
Two of those tests guard things no feature would think to check.
CI leaves no usable credential behind on the runner.
Every change goes through a pull request. Over 120 so far.
Four agent reviewers are wired to every pull request.
$ npm run test
Test Files 76 passed (76)
Tests 601 passed (601)
Duration 2.04s$ npm run check:budget
First-load JS budget · 485 KB gz per route
✓ / 437.9 KB gz (20 chunks)
✓ /about 439.7 KB gz (20 chunks)
✓ /systems 442.4 KB gz (21 chunks)
✓ /method 438.7 KB gz (20 chunks)
✓ /partner 432.3 KB gz (19 chunks)
✓ /contact 445.8 KB gz (21 chunks)
✓ /how-i-build 437.0 KB gz (20 chunks)
✓ 7 routes within budget · worst /contact 445.8 KB gz/ Keys and access · 07
A key never reaches a shell history, a log, or a chat window.
The coding agents I run are denied every env file, key, and secret command.
An unauthenticated request never reaches an admin route handler.
/ Data and money · 08
The database refuses writes by default.
A payment event cannot be forged, and cannot be counted twice.
The site builds from a clean clone with no secrets at all.
/ The live surface · 09
The one public write endpoint is rate limited.
/ Not switched on yet · 10
Every repository has gaps and a technical reader spots an all-green page in seconds. These are mine. A test in this repo fails the build if this list is ever empty, which is the only way I know to keep it honest when the page is also marketing.
No human approval is required, because there is one human.
Linting is not part of the merge check yet.
There are no browser tests.
The admin login route is not rate limited.
I do not set a content security policy or security headers.
The pre-push hook on my laptop is not a control.
The GitHub-native scanners are off: CodeQL, secret scanning, push protection.
/ Checking this page · 11
Repository paths above point into a private repo, so they are printed rather than linked: a link that 404s for every visitor is worse than no link. What stands behind them instead is a contract test that fails the build if a cited file is deleted, if a gap loses its reason, or if the ledger runs out of gaps. Some of the same files are readable in full through Source.