# Exiid OS · Exiid Labs > We build ventures and install the systems behind growth. > Build is abundant. Decisions, distribution, and compounding loops are not. > Growth architecture studio · Model transfer. > Ventures: What Exiid builds and co-owns. > Client Systems: We install defined operating systems, not disconnected production capacity. A Client Systems engagement starts with the decision, proves the riskiest assumption, then installs the product, growth, data, AI, automation, or integration layer required. Fixed scope, written stop criteria, no indefinite retainer tail. > The website is an operating-system experience: every app is a real, crawlable route. Exiid Labs is a growth architecture studio. We build and co-own selected ventures, and install the product, growth, data, AI, and integration systems we use ourselves into existing businesses. Every path starts with evidence, a defined operating outcome, and written stop criteria. Slogan: Exit the obvious · exceed the standard. Contact: yassine@exiid.com · https://www.exiid.com/contact#brief-desk ## Operator (verifiable) - Operator: Yassine ELFADILI: Founder & Operator - Prior: Software engineer turned growth-systems operator. Shipped MedLibrary, dentistry EdTech LMS from spec to production, with instrumented activation and lifecycle automation. - Background: Previously CPO at Scale (Casablanca). IIT CS. - Focus: Model transfer, validation gates, owned ventures, and scoped systems work where operating outcomes are measurable. - Promise: Briefs go directly to the operator inbox. No handoff queue, no generic intake, no nurture sequence. - SLA: Reply within 2–3 business days, next steps or a direct no-go with the reason. - Verifiable venture: MedLibrary (https://medlibrary.net) - Registry: Exiid Labs LTD (https://find-and-update.company-information.service.gov.uk/company/13081898) - LinkedIn: https://www.linkedin.com/in/elfadili-yassine/ - X: https://x.com/ElFadiliY - elfadili.com: https://elfadili.com/ ## Positioning - Category: Growth architecture studio - Method: Model transfer - Spine: Build is abundant. Decisions, distribution, and compounding loops are not. - Company statement: Exiid Labs is a growth architecture studio. We build and co-own selected ventures, and install the product, growth, data, AI, and integration systems we use ourselves into existing businesses. Every path starts with evidence, a defined operating outcome, and written stop criteria. - Short statement: We build ventures and install the systems behind growth. - Founder stage: Pre-revenue on Client Systems: No closed Client Systems, venture partnership, or advisory engagement yet. Public availability and any indicative scope are confirmed after brief review. ## Method (process transparency) - [Method hub](https://www.exiid.com/method): gates, glossary, and taxonomy map. - Method loop: Decode → Adapt → Validate (RECON) → Build / Launch / Scale (RAID), or kill - RECON: Discover + Validate: decode the reference model, test the gap, decide with evidence before build. - RAID: Build + Launch + Scale: execution only after gates clear; weak evidence stops the work. - Model Transfer Evaluation: Venture Partnership only: a scoped 2–4 week engagement that turns a co-owned transfer thesis into a go/no-go memo with a locked proof metric. Not used for Client Systems installs. - Briefs get a written reply within 2–3 business days: next steps or a direct no-go with the reason. Client Systems paid work is scoped per project and paid before it starts. - Stage 01 Discover (RECON): No build until the reference model and stop criteria are named. - Stage 02 Validate (RECON): Weak evidence is a decision, not a delay. - Stage 03 Build (RAID): Smallest product that proves transferred behavior, instrumented from day one. - Stage 04 Launch (RAID): Budget tied to learning, no launch-and-pray without measurement. - Stage 05 Scale (RAID): Expand only where unit economics and behavior metrics hold. ## Operating stack - [Operating stack hub](https://www.exiid.com/how-i-build#operating-stack) · [Research memo](https://www.exiid.com/research/operating-stack) - Borrowed frameworks, my gates, and the tooling behind them. - What I actually run, and the defaults I install. Models are rented; harnesses and eval corpora are owned. Not every tool on every engagement. - Borrowed frameworks: 14 attributed methods mapped to RECON/RAID - Studio tools: 42 across 6 layers (Runs / Install / Bench) - Model routes: 7 task lanes with Autonomy Ladder defaults - Eval harnesses: 8 rails (golden set, runtime, drift, blast-radius) - Agent surfaces: 8 runtimes with tier honesty - Hub memo: /research/operating-stack ## Operator practice (business, growth, and the build) - [How I Build](https://www.exiid.com/how-i-build): how the operator decides, distributes, and builds, each claim with somewhere to check it. - I own outcomes, not deliverables. The studio makes money when a bet works, not when a sprint closes. That changes what gets built, what gets stopped, and how it is priced. These are the parts of that which are visible from outside. - Distribution is the other half of the product. Build is abundant now. Demand is not. Every venture and every install carries the machinery that gets it in front of someone, measured well enough to know whether it worked. - I write the stop criteria before I write the code. [business] Every venture enters with a named gate, a date, and a number that would end it. Willingness to pay, market access, risk, timing. If the gate fails, the venture stops and the memo goes public. Why: A roadmap tells you what to build next. It has no opinion about when to stop, which is why most things that should have died are still being funded. Proof: The kill archive (/archive). - I take ownership positions, not billable hours. [business] The portfolio is owned or co-owned, two of them with named partner entities that carry real obligations. Client Systems work is fixed scope against a defined operating outcome. Why: An agency gets paid whether or not the thing works. That is not a character flaw, it is what the contract rewards. Ownership rewards something else. Proof: The venture register (/ventures). - I price scope with a written end, and there is no retainer tail. [business] Fixed scope, a defined operating outcome, and a written condition that closes the engagement. The ladder from a written fit read to an install is published, including what each step costs. Why: A retainer pays for presence. It quietly converts a supplier into a dependency, and the incentive to finish disappears on both sides. Proof: The offer ladder (/partner). - I publish what I killed, and the exact gate it failed. [business] Each archive entry carries the bet, the gate that failed, the date, and the memo. Not a post-mortem written for comfort, the criterion that was set in advance and then missed. Why: Every studio publishes its wins, which is why wins carry almost no information. The archive is what makes the rest of the portfolio readable. Proof: Read a kill memo (/archive). - The studio runs on the systems it sells. [business] This site, its content CMS, the ship log, the billing gateway, and the operator dashboard are the same layers a Client Systems install puts in. The implementation files are readable, not described. Why: A reference implementation a buyer can open is a different category of evidence from a deck about one. Proof: Read the source (/source). - I build loops, not funnels. [growth] A loop has to clear five criteria before it gets budget: the output has to feed the input, the cycle has to be measurable, and it has to survive without new spend. Funnels stay, but as diagnosis rather than strategy. Why: A funnel is a report on what already happened. A loop is an asset that produces the next cohort. They are priced identically and they are not the same thing. Proof: Growth architecture (/research/growth-architecture). - One channel is proven to payback before the next one opens. [growth] Channel work runs single threaded until payback is visible by cohort, then it gets written into a playbook the client's own team runs. Only then does a second channel start. Why: Running four channels at once produces activity in all four and attribution in none. Sequencing is slower for a quarter and faster for a year. Proof: Growth and marketing systems (/systems/bundles/growth-stack). - Instrumentation goes in before budget does. [growth] One North Star, a minimum instrumentation set, and cohort tracking exist before the first campaign runs. Attribution cleanup comes before attribution reporting. Why: Spend that starts before measurement can never be evaluated afterwards, only defended. The number arrives too late to change the decision it was meant to inform. Proof: North Star and instrumentation (/research/north-star-and-instrumentation). - Positioning is the first growth lever, not the last. [growth] The category, the spine, and the job the buyer is actually hiring for get written before a channel plan exists. The words on the page are treated as part of the system, not decoration on it. Why: A weak position makes every channel more expensive at once, and no amount of spend corrects it. It is the cheapest thing to fix and the last thing most teams touch. Proof: Jobs to be Done in model transfer (/research/jtbd-in-model-transfer). - Lifecycle is a system, not a campaign. [growth] CRM scoring, routing, and lifecycle loops ship wired together, with the handover playbook as a deliverable rather than an afterthought. Why: Campaigns end when the person who ran them leaves. A wired system keeps running, which is the entire difference between a marketing spend and a marketing asset. Proof: Growth and marketing systems (/systems/bundles/growth-stack). ## Engineering practice (what is enforced, and what is not) - No human reviews my pull requests. Four agents do. - Four agent reviewers read every pull request before it can merge, and none of them can approve it. What actually blocks a merge is enforced by a server rather than by a habit, and the controls I have not switched on are listed here too, with the reason. - This describes exiid-os, the repo behind this site. It is the same posture I install, not a claim about a system you already run. - As of 2026-08-07: 12 enforced, 3 partial, 2 off by choice, 5 not yet. - I cannot merge past my own check. [Enforced, verified 2026-08-07] Blocks: Any change that fails type checking or tests, pushed from any account including mine. Receipt: Branch protection · main · require status checks: Typecheck · tests; .github/workflows/ci.yml. - Every pull request runs a type check, the full test suite, and a production build. [Enforced, verified 2026-08-07] Blocks: A type error, a failing test, or a build that only works on my machine. Receipt: .github/workflows/ci.yml; npm run typecheck && npm run test. - The build fails if a page gets heavier. [Enforced, verified 2026-08-07] Blocks: A dependency that quietly adds weight to the first load of a public route. Receipt: scripts/first-load-budget.mjs; npm run check:budget. - Two of those tests guard things no feature would think to check. [Enforced, verified 2026-08-07] Blocks: An animation library creeping onto the eager path, and an em dash reaching customer-facing copy. Receipt: src/lib/motion-budget.test.ts; src/lib/content/punctuation.test.ts. - CI leaves no usable credential behind on the runner. [Enforced, verified 2026-08-07] Blocks: A compromised action or dependency reading a token out of the build environment. Receipt: .github/workflows/ci.yml. - Every change goes through a pull request. Over 120 so far. [Enforced, verified 2026-08-07] Blocks: An untracked change to production with no diff, no checks, and no record. Receipt: .github/PULL_REQUEST_TEMPLATE.md; Branch protection · main · include administrators. - Four agent reviewers are wired to every pull request. [Partial, verified 2026-08-07] Blocks: A bug or an unsafe pattern that the type checker and the tests both allow through. Reason: They are advisory, not required. None of them is a required status check, so a merge does not wait on them, and their coverage is uneven in practice: on the pull request that shipped this page, two completed, the security reviewer returned neutral, and Bugbot reported its own run as failed. An advisory reviewer that silently does not run is worth less than the badge suggests, which is why this is partial rather than enforced. Receipt: Checks on every PR · Cursor Bugbot, Cursor Security Reviewer, Cursor Approval Agent, [code]smith. - No human approval is required, because there is one human. [Off by choice, verified 2026-08-07] Blocks: Nothing. This is the gap, stated plainly. Reason: A required approval that I grant myself is a checkbox, not a review, and a checkbox dressed as a control is worse than an absent one. What covers part of it: the check is required, admins are not exempt, every change still goes through a pull request, and four agent reviewers read it first. What none of that covers: a logic error that the type checker, the tests and every agent all miss will ship. That is the real cost of a one-person shop and no setting removes it. Receipt: Branch protection · main · required approving reviews: 0. - Linting is not part of the merge check yet. [Not yet, verified 2026-08-07] Blocks: Nothing today. It would catch unsafe React patterns the type checker allows through. Reason: The step was left out while the existing lint debt was paid down, and the note in the workflow file still cites the original count. As of the verification date the real number is 7 errors and 10 warnings across 15 files, so the reason has outlived itself. Turns on when: The error count reaches zero. At 7 that is a sitting, not a project, and it is the next thing on this list. Receipt: .github/workflows/ci.yml; npm run lint. - There are no browser tests. [Not yet, verified 2026-08-07] Blocks: Nothing today. They would catch regressions in the hand-rolled pointer gestures. Reason: The gestures behind the mobile sheets and back swipes are covered only by a render-level smoke test. Adding real browser coverage is work rather than a toggle, and it has been losing to buyer-facing work. That is a priority call, not an oversight. Turns on when: The first gesture regression that reaches production. If that happens I will say so here. Receipt: none. - A key never reaches a shell history, a log, or a chat window. [Enforced, verified 2026-08-07] Blocks: The most common way a credential leaks, which is a human pasting it somewhere convenient. Receipt: docs/ENV.md; scripts/env.sh. - The coding agents I run are denied every env file, key, and secret command. [Enforced, verified 2026-08-07] Blocks: An agent reading a live credential into a transcript that then leaves my machine. Receipt: .claude/settings.json. - An unauthenticated request never reaches an admin route handler. [Enforced, verified 2026-08-07] Blocks: A handler bug turning into an exposure, because the request stops before the handler. Receipt: src/middleware.ts. - The database refuses writes by default. [Enforced, verified 2026-08-07] Blocks: A leaked public key turning into a write, because no public write path exists to begin with. Receipt: supabase/migrations/001_admin_content.sql; supabase/migrations/002_billing_fulfillment.sql; supabase/migrations/003_products.sql. - A payment event cannot be forged, and cannot be counted twice. [Enforced, verified 2026-08-07] Blocks: A spoofed fulfillment call, and a retried webhook granting the same thing twice. Receipt: src/lib/billing/fulfillment.ts; supabase/migrations/002_billing_fulfillment.sql; npm run contract:verify. - The site builds from a clean clone with no secrets at all. [Enforced, verified 2026-08-07] Blocks: A build that silently depends on my laptop, and a content outage taking the site down with it. Receipt: src/lib/content/loaders.ts; .github/workflows/ci.yml. - The one public write endpoint is rate limited. [Partial, verified 2026-08-07] Blocks: A script pointing the brief form at someone else's inbox and flooding it. Reason: The limiter is in-memory and best effort. On serverless each instance keeps its own window, so a determined flood spread across instances gets more through than the number suggests. A hard guarantee needs a rule at the edge, and that is written in the file rather than glossed over. Receipt: src/lib/rate-limit.ts; src/app/api/brief/route.ts. - The admin login route is not rate limited. [Not yet, verified 2026-08-07] Blocks: Nothing today. It would slow credential stuffing against the operator login. Reason: The limiter exists and is wired to the public brief endpoint only. The admin routes sit behind a Supabase session and an email allowlist, so a guess has to beat both, but that is a reason it has not burned me rather than a reason it is fine. Turns on when: The same limiter applied to the auth and password reset routes. It is a small change and it is on this list so it does not stay forgotten. Receipt: src/lib/rate-limit.ts. - I do not set a content security policy or security headers. [Not yet, verified 2026-08-07] Blocks: Nothing today. A policy would contain the blast radius of an injected script. Reason: Whatever transport security is in place comes from the hosting edge by default, not from anything in this repo. The app config sets no policy of its own, and I would rather say that than let a platform default read as my work. Turns on when: A policy authored in the app config and checked into the repo, so it is a reviewable diff like everything else here. Receipt: next.config.ts. - The pre-push hook on my laptop is not a control. [Off by choice, verified 2026-08-07] Blocks: Nothing that the server does not already block. It is listed so it is not mistaken for a control. Reason: There is a hook that refuses force pushes and direct pushes to main. It is untracked, it lives on one machine, and a fresh clone gets none of it. A check that exists only on my laptop is a habit. The server-side branch protection is the thing that actually holds, which is why it is listed first on this page. Receipt: none. - I get dependency alerts, but nothing patches them for me. [Partial, verified 2026-08-07] Blocks: Nothing automatically. The alerts arrive, the fixes are manual and therefore as slow as I am. Reason: Alerts are on. Automatic version and security pull requests are not, because an unattended stream of update branches on a repo with one reviewer is a queue rather than a fix. That reasoning stops being true once the open list is at zero, which is the point of the trigger below. Receipt: package.json. - The GitHub-native scanners are off: CodeQL, secret scanning, push protection. [Not yet, verified 2026-08-07] Blocks: Nothing today. Push protection in particular would stop a committed key at the push itself rather than after it. Reason: Not an absence of review, a gap in a specific layer. Agent reviewers read every pull request, including a security reviewer, but they are advisory and they reason about the diff. A native scanner is deterministic, runs against the whole tree, and does not have an off day. Two other things reduce the odds without replacing it: keys never enter the repo, because they live outside it and the agents are denied the files, and dependency alerts are on and read. Turns on when: The three toggles switched on for this repo and the open advisory list cleared, after which these rows change state and get a fresh date. Receipt: none. ## Client Systems (outcome systems composed from the stack we run) - Software and internal apps (/systems/bundles/operator-stack): Custom tools your team can run every week. Examples: Internal ops apps; Client or partner portals; Workflow tools between teams. Capabilities: Intake and assignment surfaces; Status and client-facing updates; Workflow tools between teams. · when: Work lives in spreadsheets and chat, or ship cadence is stuck without a real product surface. · outcome: A shipped app or tool one owner can run without a ticket queue. - Business systems (/systems/bundles/odoo-stack): ERP and ops workflows that match how you actually work. Examples: Inventory and sales workflows; Invoicing and payments workflows; Warehouse and order ops. Capabilities: Inventory and sales order flows; Invoicing and payment paths; Warehouse and fulfillment ops. · when: Sales, stock, and finance disagree, or you are replacing a patchwork of tools with one system. · outcome: Connected ops workflows with owners and a closed month-end path. - Growth and marketing systems (/systems/bundles/growth-stack): Demand loops you can measure and repeat. Examples: CRM and lifecycle loops; Channel playbook; Campaign instrumentation. Capabilities: Landing and funnel wiring; CRM scoring and routing; Lifecycle loops; Channel playbook; Campaign instrumentation. · when: Ads and email are active but loops stall, or nobody can show payback by channel. · outcome: Visible payback by channel, with a playbook your team can run again. - Data and dashboards (/systems/bundles/signal-stack): Numbers you can decide on. Examples: Decision dashboards; Attribution cleanup; Weekly operator scorecard. Capabilities: GA4 and attribution cleanup; Decision dashboard; Weekly operator scorecard; Payback view by channel. · when: Dashboards disagree, or spend scaled before signal did. · outcome: One source of truth for the decisions that move budget. - [Client Systems](https://www.exiid.com/systems#bundles) ## Commercial availability - Founder stage: Pre-revenue on Client Systems: No closed Client Systems, venture partnership, or advisory engagement yet. Public availability and any indicative scope are confirmed after brief review. - Client Systems plain path: We check fit → we scope the decision → we install the system. - Fit Read artifact: A short written read: fit, not fit with reason, or what to clarify, plus a prioritized list of what is broken first. You keep that list either way. - Fit Read: You tell us what you want installed (software, business systems, growth, or dashboards). We reply in writing: yes this fits, no with a reason, or what to clarify, plus a prioritized list of what to fix first. You keep that list either way. Free. No commitment. - Decision Diagnostic: If it fits, we scope the next paid step in writing for that project: what is broken, what to build, what done means, and when we would stop. Fee is per project. Paid before work starts. Ends with a clear go or no-go before bigger work. - Install: If we go, we build and connect the system to a defined outcome, then run it for a period or hand it to your team. Fixed scope confirmed in writing, paid before work starts, no retainer tail. - Client Systems availability: fit read only; the paid Decision Diagnostic, Proof Sprint, and System Install are not open currently - Advisory indicative: Scoped after brief review (Indicative advisory sprint · 2–4 weeks · written go/no-go memo · fee confirmed in writing) - Client Systems first step: Decision Diagnostic not open currently; Client Systems brief for fit only - Client Systems next step: Send a Client Systems brief for a fit read. - Partner venture next step: Send a Partner venture brief for a fit read. Paid Model Transfer Evaluation is not open currently ## The six engines - Opportunity Engine: Finds proven business models paired with markets that lack them. Scans corridors, names reference models, and maps where the same mechanics could win again before anyone builds. - Validation Engine: Tests demand before major investment. Smoke offers, concierge runs, and paid signal tests against named thresholds, weak evidence is a decision, not a delay. - Product Engine: Ships the smallest product that proves transferred behavior · SaaS, AI products, EdTech, marketplaces. Instrumentation from day one; activation before expansion. - AI Engine: Deploys agents, workflows, and automation on explicit autonomy boundaries. One operator runs systems that used to need teams, judgment on fit, ethics, and kill calls stays human. - Growth Engine: Designs acquisition, retention, and lifecycle as loops, not campaign bursts. Instrumentation before spend; compounding only where payback is visible by cohort. - Scale Engine: Turns validated products into operating businesses. Channel expansion where unit economics hold; operational architecture that survives growth; discipline to kill what stalls. ## Operating layers (reference catalog behind Client Systems) - [Validation OS](https://www.exiid.com/systems/validation-os): Prove demand before build capital moves. - [Product OS](https://www.exiid.com/systems/product-os): Ship the smallest product that proves the behavior. - [AI OS](https://www.exiid.com/systems/ai-os): Operational AI that compresses teams into systems. - [Growth OS](https://www.exiid.com/systems/growth-os): Compounding loops, not campaign theater. - [Analytics OS](https://www.exiid.com/systems/analytics-os): Decisions on evidence, not dashboards for show. - [GTM OS](https://www.exiid.com/systems/gtm-os): Controlled launches that prove repeatability. ## Ventures (operating assets Exiid builds and runs) - [Growth Automation](https://www.exiid.com/ventures/growth-automation-os): Internal growth stack across Exiid ventures; available to operators through Build installs (RevOps / MarTech, International, stage: building) - [Carwella](https://www.exiid.com/ventures/carwella): B2B and B2C auto parts ecommerce plus mechanic marketplace, co-owned with DATAPARTS SARL, live in closed beta (Automotive commerce, Auto parts buyers and mechanics (closed beta), stage: building) - [MedLibrary](https://www.exiid.com/ventures/medlibrary): Subscription EdTech for dentists: courses, ebooks, certificates, and team seats at medlibrary.net (Healthcare EdTech, Dentists and dental practices, stage: building) - [BaseCommerce](https://www.exiid.com/ventures/basecommerce): Own your WooCommerce storefront: theme plus curated suite modules, live in closed beta on basecommerce.io (eCommerce infrastructure, WooCommerce merchants · closed beta, stage: building) - [Syva](https://www.exiid.com/ventures/syva): Private facial strategy platform: what is distinctive, what can improve, what to do first, live in closed beta (Consumer · facial strategy, Adults seeking non-surgical facial improvement (closed beta), stage: building) - [Tabloo](https://www.exiid.com/ventures/tabloo): Multi-tenant café OS for menu, reviews, screens, Wi-Fi, events, and ads, live in closed alpha (Hospitality · venue OS, Cafés and restaurants (closed alpha), stage: building) - [InsightHub](https://www.exiid.com/ventures/insighthub): Private · internal decision tool: score opportunities before Exiid builds (Market intelligence, Exiid founders and operators (private · internal), stage: building) - [eCommerce Attribution](https://www.exiid.com/ventures/ecommerce-attribution): Attribution and payback visibility for GCC eCommerce operators outrunning their reporting stack (MarTech, GCC & Eastern Europe, stage: validation) - [Knowledge Commerce Stack](https://www.exiid.com/ventures/knowledge-commerce-stack): Creator monetization infrastructure for experts still on patchwork tools in MENA corridors (Creator infrastructure, MENA & emerging corridors, stage: validation) - [Market Intelligence Lab](https://www.exiid.com/ventures/market-intelligence-lab): Continuous scan of proven models and underserved corridors, scored theses, not slide decks (Market intelligence, Cross-corridor, stage: research) - [Wild Friend](https://www.exiid.com/ventures/wild-friend): Wildlife friendship and conservation platform, co-owned with BORACARE FOUNDATION LTD, active soon (Conservation · civic tech, Wildlife supporters and gift buyers, stage: building) ## Products (use cases inside Ventures) Products are not a third lane and are not aliases for Client Systems. A distribution channel is live only with a public URL and verification date. - MedLibrary (Operating): for Dentists and dental practices; job: Find courses, ebooks, and certificate paths that fit a working dentist's week, including team seats.; outcome: Complete relevant learning paths and renew because activation and completion stay visible.; proof: Activation, path completion, and subscription renewal; distribution: Web: https://medlibrary.net. - BaseCommerce (Operating): for WooCommerce merchants and agencies in closed beta; job: Run a coherent theme-plus-module suite on WooCommerce they still own.; outcome: Ship and renew a licensed storefront stack whose marketing, licensing, and account surfaces stay on basecommerce.io.; proof: Paid licence activation and renewal on the BaseCommerce perimeter; distribution: no verified public distribution listing. - Carwella (Operating): for Auto parts buyers, workshops, and mechanics (closed beta); job: Find and buy the right parts, and connect with mechanics when the job needs hands.; outcome: Complete purchases and marketplace matches without leaving the co-owned stack.; proof: Order completion and marketplace match rate; distribution: no verified public distribution listing. - Syva (Operating): for Adults who want a private, evidence-based facial improvement plan (closed beta); job: See what is distinctive, what can realistically improve, and what to do first.; outcome: Complete a sample or paid report path and act on ranked non-surgical priorities with visible confidence.; proof: Sample-to-report conversion and plan action within 90 days; distribution: no verified public distribution listing. - Tabloo (Operating): for Café and restaurant operators (closed alpha); job: Run menu, reviews, screens, Wi-Fi, events, and ads as one venue OS.; outcome: Guests get a coherent digital table experience; operators manage one multi-tenant stack.; proof: Pilot venue day-1 activation and weekly manager return; distribution: no verified public distribution listing. - InsightHub (Operating): for Founders and operators inside Exiid (private · internal); job: Score an opportunity and get a start / refine / avoid read before building.; outcome: Advance only ideas that clear an explainable evidence gate.; proof: Ideas advanced, refined, or killed against the score gate; distribution: no verified public distribution listing. - Wild Friend (Building): for Wildlife supporters and gift buyers; job: Discover a species, support a verified program, and receive evidence-backed updates.; outcome: Return within 90 days after a verified update.; proof: Verified update received and return within 90 days; distribution: no verified public distribution listing. - Growth Automation (Operating): for Lean venture and growth operators; job: Run repeatable growth operations while keeping positioning and kill calls with the operator.; outcome: One operator can manage measurable growth loops without adding premature headcount.; proof: Channel payback and repeatable lifecycle throughput; distribution: no verified public distribution listing. - eCommerce Attribution (Validation): for GCC and Eastern European ecommerce operators; job: See acquisition payback by channel and cohort before expanding spend.; outcome: Scale only the channels whose economics remain visible and credible.; proof: Stable CAC payback visibility by channel and cohort; distribution: no verified public distribution listing. - Knowledge Commerce Stack (Validation): for Experts with an audience in MENA and emerging corridors; job: Sell and deliver a structured knowledge offer through a locally usable system.; outcome: Launch with local payment rails, mobile-first delivery, and measurable completion.; proof: Paid conversion, willingness to pay, and completion; distribution: no verified public distribution listing. - Market Intelligence Lab (Research): for Operators evaluating proven models for underserved markets; job: Turn corridor research into a scored thesis that can be validated, shelved, or killed.; outcome: Advance only the transfer theses that clear a written evidence gate.; proof: Theses advanced to paid validation or shelved against a written gate; distribution: no verified public distribution listing. ## How We Work (lanes and structures) - [How We Work](https://www.exiid.com/partner): method, Client Systems journey, boundaries. Not three equal track cards. - Partner-originated ventures: https://www.exiid.com/ventures#partner-path - Commercial hierarchy: Client Systems primary; partner-originated ventures nest under Ventures; Advisory is decision-only and secondary - Primary · Client Systems: For existing businesses: we install the system around a bottleneck. Fixed scope. Clear outcome. Examples include Odoo or ERP workflows, internal apps, dashboards, and growth loops. Not a task list or retainer. Availability: Fit Read free · paid next step scoped per project and paid before work starts.. Next: Send a Client Systems brief for a fit read. - Secondary · Partner venture: Bring a proven model, market access, domain advantage, or distribution. Exiid brings evaluation, product, growth machinery, and operating discipline. If the evidence clears, we co-own the venture. Availability: Not merchandised while the paid gate is closed.. Next: Send a Partner venture brief for a fit read. - Secondary · Advisory: Bring a consequential go or no-go decision. Exiid evaluates the evidence and returns a written recommendation with the reasoning attached. Availability: Scoped after brief review.. Next: Send an Advisory brief for scope review. ## Research (public knowledge base) - [Operating stack hub](https://www.exiid.com/research/operating-stack): Borrowed frameworks, studio tools, model routes, and eval harnesses mapped to RECON/RAID, with tier honesty and receipts on every row. - [AI models and harnesses](https://www.exiid.com/research/ai-models-and-harnesses): Model routing by task lane, agent surfaces we run, eval harness catalog, and promotion rules: models are rented, harnesses are owned. - [Enterprise tooling stack](https://www.exiid.com/research/enterprise-tooling-stack): Six studio tool layers with Runs, Install, and Bench tiers, plus selection criteria for instrumented, portable, gated tooling. - [JTBD in model transfer](https://www.exiid.com/research/jtbd-in-model-transfer): How Jobs-to-be-Done decodes buyer jobs, forces, and outcomes before smoke offers and concierge specs in RECON. - [Theory of Constraints for operators](https://www.exiid.com/research/theory-of-constraints-for-operators): Name the bottleneck, exploit before you elevate: why first paid Diagnostic beats more marketing when capital is scarce. - [Shape Up at Exiid](https://www.exiid.com/research/shape-up-at-exiid): Fixed-time appetites for Evaluations and validation sprints: variable scope toward proof, circuit breakers, and kill over creep. - [North Star and instrumentation](https://www.exiid.com/research/north-star-and-instrumentation): One primary outcome metric, AARRR as diagnostic layers, and the five-event Minimum Instrumentation Set before launch spend. - [One operator, many agents](https://www.exiid.com/research/one-operator-agentic-stack): How Exiid runs a one-person company without headcount theater: agentic orchestration, five stack layers, the Ventures and Client Systems lanes, and the governance rails that keep autonomy honest. - [The Market Transfer Framework](https://www.exiid.com/research/market-transfer-framework): Exiid's signature method for adapting proven online business models into underserved markets: five selection criteria, the Localization Stack, named failure modes, and a scored go/no-go. - [AI-First Business Models](https://www.exiid.com/research/ai-first-business-models): What changes when agents are the operating core, not a feature: margin migration, exception-staffed teams, a four-model taxonomy, and the moats that compound when intelligence is rented. - [AI Systems Design](https://www.exiid.com/research/ai-systems-design): How Exiid designs operational AI systems for ventures: workflow-first decomposition, the Autonomy Ladder, eval loops, blast-radius containment, and where automation pays. - [Growth Architecture](https://www.exiid.com/research/growth-architecture): Growth as a designed system, not a bag of tactics: four layers, four loop classes, a five-point loop test, and the gate that decides what gets automated. - [Validation Playbooks](https://www.exiid.com/research/validation-playbooks): Three demand tests, smoke offers, concierge MVPs, paid signals, plus threshold metrics and kill criteria that prove buyers exist before build capital moves. - [SEO After AI](https://www.exiid.com/research/seo-after-ai): How organic acquisition works when queries end in AI answers: the Citation Stack, llms.txt, entity authority, the Summarization Test, and distribution beyond the SERP. - [Transfer Readiness Checklist](https://www.exiid.com/research/transfer-readiness-checklist): Operator checklist for deciding whether a proven model deserves validation spend, six checks across model, market, advantage, and proof point, scored into three tiers. - [GCC and Eastern Europe: attribution before automation](https://www.exiid.com/research/gcc-ecommerce-attribution-first): Why regional eCommerce operators need payback clarity before automation breadth, and the attribution signal that proves the transfer. - [Client Systems vs Advisory vs Venture Partnership](https://www.exiid.com/research/jv-advisory-venture-build): How to choose between an installed client system, a co-owned venture partnership, and decision-only advisory. The outcome and ownership model drive the structure. - [When AI deserves systems work](https://www.exiid.com/research/ai-model-sprint-fit): AI belongs in systems work only when it changes cost, speed, distribution, customer experience, operations, or the offer itself. A fit test for separating leverage from tool theater. - [What happens in a Model Transfer Evaluation](https://www.exiid.com/research/model-transfer-evaluation-process): How a fit check turns a brief into a go/no-go decision in 2–3 business days, what the decision package contains, and why a direct no-go protects capital. - [RECON before roadmap](https://www.exiid.com/research/recon-before-roadmap): Why Exiid pressure-tests model, market, channel, and risk before turning a transfer thesis into a build plan. A RECON sprint ends in build, adapt, partner, or stop. - [Is this model worth transferring?](https://www.exiid.com/research/is-this-model-worth-transferring): A four-gate checklist for deciding whether a proven model deserves validation or should stay on the shelf: legible model, mis-served market, specific advantage, named proof. - [Ethical transfer vs cloning](https://www.exiid.com/research/ethical-transfer-vs-cloning): How Exiid adapts proven mechanics without IP theft: decode, adapt, respect IP, test, plus the red lines that get a transfer refused outright. ## Building in public (the ship log) Abstracted operator notes, not a changelog. JSON feed at https://www.exiid.com/building/feed.json. - [Don't ask an agent to keep a secret it can see](https://www.exiid.com/building/dont-ask-an-agent-to-keep-a-secret-it-can-see): The reliable way to stop an automated system from leaking something is to make the leak structurally impossible, not to instruct against it. - [Review the gate, not the keystroke](https://www.exiid.com/building/review-the-gate-not-the-keystroke): Watching an agent type is theater. I moved my attention to the checkpoints where a wrong call actually costs something. - [A system earns its keep by deleting a decision](https://www.exiid.com/building/a-system-earns-its-keep-by-deleting-a-decision): The tools I keep are not the ones that save minutes. They are the ones that remove a choice I was tired of making. - [Publish the kill, not just the win](https://www.exiid.com/building/publish-the-kill-not-just-the-win): Anyone can post a launch. The receipts that build trust are the bets I called dead on a gate I wrote in advance. ## Killed ventures (the archive) Kill criteria are written before the build, failed gates are published at https://www.exiid.com/archive. - [Creator CRM](https://www.exiid.com/archive/creator-crm) (2025 Q2 → 2025 Q3): Course creators in francophone markets would pay for a CRM that treats a launch calendar, not a sales pipeline, as the primary object. Killed: Willingness-to-pay gate, fewer than 5 of 20 discovery calls would prepay a pilot. - [GCC Returns OS](https://www.exiid.com/archive/gcc-returns-os) (2025 Q3 → 2025 Q4): E-commerce returns automation, proven in Western Europe, would transfer to GCC merchants suffering 2–3× the return rates with none of the tooling. Killed: Market-access gate, no verifiable partner with merchant relationships materialized inside the six-week window. - [MedTranscribe](https://www.exiid.com/archive/med-transcribe) (2025 Q4 → 2026 Q1): Clinical-note transcription tuned for Darija–French code-switching would win Moroccan private clinics before global players localized. Killed: Risk gate, health-data residency requirements pushed compliant infrastructure cost past the entire validation budget. ## Operating principles - Decode: Study what already wins, offer, funnel, pricing, distribution before inventing. - Exit the obvious: Leave crowded categories; play where demand exists but execution lags. - Exceed the standard: Raise execution, positioning, systems, and speed past the baseline. - Prove before scale: Validate demand, risk, and economics before budget moves. - Use AI with discipline: Compress decode, build, and learn. Judgment on fit, ethics, and kill calls stays human.