⚙ the Engine Room
A visitor asked the best possible question — and the answer
A visitor asked the best possible question: "there's a lot
going on — which part shows me Autonomi?" This page is the answer. One picture of what
actually runs under every door on the hub, in plain words, with the honest parts included.
(He came back: "I like the use of multiple systems together, and the split between Arweave
& Autonomi based on size of file." — the page did its job, and the loop is on the record.)
The whole estate, one engine diagram: the identity root, the
rust kernel, the rails that carry data and value, and which door runs on what — measured, not
claimed. Born from a stranger's question: "which part should I look at to see an
interesting use of Autonomi?"
Architecture disclosure: bzDiD root → rust coordination
kernel → adapter layer (storage, chains, relays) → dApps. Storage routing is a price-break
function; per-surface rail usage below is measured by endpoint grep, dated, not
self-reported. Bootstrap dependencies and unmigrated relays are named as debts, not hidden.
THE ORGANS — live status, read from where you sit
…organs · read live from your network, just now
The status law — what each status means and does not
every status on this board says what it means AND what it does not mean — a status board must never confuse "this is broken" with "I can't see it from here". these reads come from YOUR network, your browser, just now: a status here is a fact about the road as much as the organ.
the estate's heartbeats, drawn live — green when a road answers, lilac when a road goes quiet. never red for silence: silence is a guard, not a scream.
probes: no-cors reach per road · NIP-11 identity (Accept: application/nostr+json) on each hive · the compute gate's 401 as the lock's own pulse. observer = your browser; every result is a path-relative fact.
alivemeans: it answered this page just now, over the road shown. does NOT necessarily mean it will answer tomorrow, or from every road — an answer is a moment, not a promise.
guard · no answermeans: this road gave no answer. does NOT necessarily mean the organ is down — the road can be the fault. the same box answered the whole planet while one filtered network saw nothing.
via fallbackmeans: the brand road went dark on your network; the backup road answered. does NOT mean down — up and unreachable are two different facts.
other answermeans: it answered, but not in the expected shape. does NOT mean broken — versions and answers differ.
not watchedmeans: this page keeps no eye on this organ. does NOT mean broken or idle — absence of a watch is not absence of function.
hazardmeans: the two roads disagree about what this organ is. this one means exactly what it says — a split identity is the one state this board calls a hazard.
THE SHAPE — root below, everything else above
🐝 bzDiD — the identity root
self-authenticating identity (Self-Auth + DiD), built to survive the loss of
any layer above it — including any single storage network. The root is yours;
everything else is replaceable. see it live
▼
the coordination kernel — rust
a public workspace of ~36 crates. Adapters plug into it; none of them is
load-bearing for identity. source
▼
the adapter rails — storage, value, relays
Storage routes by measured economics: ◈ Arweavecarries small public immutable data — priced per byte, one endowment. ⬢ Autonomi read at source. The crossover between the two is therefore a FUNCTION, not a constant — it moves with the ANT price and with network fullness — so the estate measures per job and lets the receipts keep the history. Private immutable data always routes to Autonomi (self-encrypted). The routing law exists for one person — the poor starving artist: an inscription-sized artwork must cost cents to keep forever, and a lifetime's archive must not cost a lifetime. The split is not cleverness; it is who this was built for. Value and state: ▣ Vaulta
(RAM/CPU/NET resource model — the .b registry lives here) ·
⟠ Base + Ethereum(the on-chain art the gallery reads
keylessly) · ₿ Bitcoin(read via Esplora in the
museum).
Voice: ◆ Hive longform ·
relays.
How storage routes are chosen — measured economics, not habit
carries large public and all private immutable data — priced per RECORD by node fullness, then ×3: ADR-0008 (PROPOSED, 2026-07-28, WithAutonomi/ant-node) sets a calibrated quadratic in the node's COMMITTED key count — price_per_record(n) = 0.00390625 + 0.03515625×(n/6000)² ANT, per its signed storage commitment, not raw files — and the client pays 3× the median quote; one record is up to 4 MiB, so a ~100 kB file is one record; merkle batches (64+ chunks) pad to a power of two, so 65 chunks pay as 128.▼
the dApps — every card on the hub
static, keyless pages. No logins, no custody, nothing to breach — each one a
read-and-compose window over the rails below it. back to the hub
The honest parts — stated before anyone asks
The honest parts, stated before anyone asks:
GitHub Pages currently serves these pages — a temporary bootstrap crutch, and any small
server you might find behind a feature is the same. The mirror lane already hashes and stages
the evidence corpus for permanent storage, and the bSky/Nostr relays are the last planned
migration — once anchored to the chains and ANT/AR, redeploying relays and nodes becomes
autonomous. A page that hid its scaffolding would be advertising; this one is a receipt.
FOLLOW ONE FILE — the data loop, one journey, three depths
where is my data, who can see it, what happens next? this loop answers the three questions for any file you bring. tap a stage to look inside — nothing is sent, nothing changes; this is a map, not a machine.
the estate as a living system: data enters like breath, crosses selective membranes, becomes useful work, leaves evidence behind, and the result feeds the next decision. homeostasis, not hustle — a healthy loop knows how to wait.
one control loop over four circuits — payload, authority, evidence, value — each stage expandable to real components, policy boundaries and implementation status. proposed architecture is labeled as such; only receipts claim verified.
choosing a depth changes the explanation only — never permission, privacy, or payment. this picture is a recorded explanation, not live telemetry: nothing here is watching anything right now.
four circuits, never confused:
● payload — what is being worked on · · ◇ evidence — what actually happened, and how we know · ○ value — resources, charges, settlement
↺ the loop closes — the result feeds the next decision, and waiting is a healthy state here, not a failure
select a stage above to inspect it
ONE REAL FILE — the first source-backed example
every number on this card is read mechanically from the intake and quote receipts, never re-typed by hand; a source that is absent says so instead of guessing
WHERE AUTONOMI IS IN THIS ESTATE, RIGHT NOW — the direct answer
1 · The founder's own vault runs on it today — personal data storage through the
Autonomi App, with a hardware-wallet payment lane spec'd so that no key ever leaves the
Trezor: the network's own external-signer flow prepares and finalizes while the device
signs (SPEC-AUTONOMI-TREZOR-1).
2 · The evidence commons is staged for it — 20 government primary documents (the citations our science surfaces stand on) harvested, sha256-hashed into an append-only public manifest, awaiting the one Trezor signature that puts them beyond any administration's delete key.
3 · The private-data doctrine matches the network's — Autonomi's DataMap-held private immutable data is the storage-layer twin of this estate's law that raw personal data is sealed to its owner, never to an operator.
4 · This sprint's receipts land the estate write-path — read-path receipt first (zero keys, zero cost), local devnet end-to-end second, then one founder-signed public upload. Each lands as a receipt in the open repo, dated, reproducible.
5 · And the boundary, stated: nothing in this estate's pages holds an Autonomi key or posts autonomously — the external-signer ceremony is the only write, and a human hand is the gate. That is a design law, not a limitation.
2 · The evidence commons is staged for it — 20 government primary documents (the citations our science surfaces stand on) harvested, sha256-hashed into an append-only public manifest, awaiting the one Trezor signature that puts them beyond any administration's delete key.
3 · The private-data doctrine matches the network's — Autonomi's DataMap-held private immutable data is the storage-layer twin of this estate's law that raw personal data is sealed to its owner, never to an operator.
4 · This sprint's receipts land the estate write-path — read-path receipt first (zero keys, zero cost), local devnet end-to-end second, then one founder-signed public upload. Each lands as a receipt in the open repo, dated, reproducible.
5 · And the boundary, stated: nothing in this estate's pages holds an Autonomi key or posts autonomously — the external-signer ceremony is the only write, and a human hand is the gate. That is a design law, not a limitation.
WHICH DOOR RUNS ON WHAT — measured 2026-08-21, not self-reported
Where each row comes from — a sweep of the page’s actual code
Each row is from an endpoint-and-content sweep of the page's actual code on
the date shown — a surface earns a chip by carrying the rail, not by claiming it.
No chips at all is its own achievement: the science surfaces (bFood, bEarth, the
symposium, the university) are ∅ zero-rail — pure static
computation over cited records, recomputable by any stranger with no network at all.
| door | rails under it | what the rails do there |
|---|---|---|
| gallery · explorer · market · organ · studio | ⟠ base⟠ eth | keyless eth_call reads of fully on-chain ERC-20i art — nine families, two chains, no indexer between you and the contract |
| museum · workbench | ⟠ base·eth₿ btc▣ vaulta◈ ar | the cross-chain reading room — what "on-chain" actually means, receipted per class |
| reader · catalog · dids · keys | ▣ vaulta | the .b registry, Self-Auth + DiD identity, and the onboarding walk |
| bQueenBee · pulse · review | ◆ hive | the hive's public voice and the Royal Guard's review rails — relays are the last planned migration to chain/ANT/AR anchors |
| bIQ · bTranslated · bFactory · recover | ⬢ ant◈ ar▣ vaulta | the composer surfaces that document and route the storage rails (recover is deliberately zero-network at run time) |
| bFood · bEarth · symposium · university · listening | ∅ zero-rail | pure computation over cited records — nothing to trust but the arithmetic, which is the point |
| b4b · farmers · hearth | ⟠ base | the Base-lane alpha (the Coinbase-submission candidate) and the community floors |
LICENSING — fenced engine, open rails (the estate shows its own reasoning, 2026-08-29)
Why we license this way — in plain words
Why we license this way, in plain words: the part of this
estate that handles money — the meter that bills, the vouchers you prepay, the gate that
checks keys — is fully readable by anyone, today, but its commercial use waits behind
a four-year window. Nobody can take our accounting engine and run it for profit on day one;
everyone can read every line of it, audit it, and learn from it. The parts you'd want to
build on — the wallet, the chain adapters, the Arweave signer — are open from day one,
free for anyone to use, copy, and fold into their own work. Fenced engine, open rails.
One sentence per side: the money machinery is readable now,
forkable-for-profit never (four years protected, then it opens to GPL); the rails everyone
interoperates through are Apache-2.0 open from the first minute. Adoption wants the rails
everywhere — and wants the engine honest, which readable-but-fenced delivers.
The terms, exactly as staged in the tree: the
commercial moat (
scripts/buzz-meter/ — meter.py the receipt/voucher/tithe engine,
rate_set.json the pricing law, gate.js the per-key door) carries Business Source License
1.1: Licensor Travis Mark Remington <lovis@skaists.dev>; copy, modify,
redistribute, and non-production use granted; production use per the Additional Use Grant
(the one open IP-lawyer item — the 10% tithe coupling); Change Date =
August 29, 2030 (the publish commit, 2026-08-29, + four years);
Change License = GPL-2.0-or-later — on the Change Date the
work re-licenses itself, no gesture needed. The rails (surfaces/wallet.html
including the spend-cap engine, the three rail adapters, the first-party Arweave signer)
carry Apache-2.0 — patent grant included, open now. Files where GitHub reads them:
/LICENSE (Apache-2.0, repo root) · /NOTICE ·
scripts/buzz-meter/LICENSE (BSL 1.1, directory-scoped) · headers on every
manifest file. Status: PUBLISHED 2026-08-29, the founder's deliberate
publish — the BSL window is live; the moat opens to GPL-2.0-or-later on
August 29, 2030.
Full reasoning + the lawyer flags:
LICENSING-PROPOSAL-2026-08-29.md.| path | license | opens |
|---|---|---|
| scripts/buzz-meter/meter.py · voucher_escrow.py · rate_set.json · gate.js | BUSL-1.1 | GPL-2.0-or-later on August 29, 2030 (the Change Date); readable + non-production now |
| surfaces/wallet.html (+ spend-cap engine) · wallet-adapter-vaulta.js · -hive.js · -arweave.js · arweave.js | Apache-2.0 | day one — use, copy, modify, fold into your own work |
The precedent — every line below reads at source
The precedent, verified at source 2026-08-29 (every
line below read from the project's own license file, not recalled):
Uniswap v4-core ships BUSL-1.1 — Change Date the
earlier of 2027-06-15 or an ENS-specified date, Change License MIT — while
v4-periphery is MIT today: the exact fenced-core/open-periphery shape
(
licenses/BUSL_LICENSE, read at source). Uniswap v3-core proves the window
closes as designed: its BSL carried Change Date 2023-04-01, now passed — the work is
GPL-2.0-or-later today (LICENSE read at source: "GNU General Public License v2.0 or
later"). MariaDB authored the BSL and its covenants govern any use of the text —
parameters only, terms unmodified (mariadb.com/bsl11, read at source). The pattern —
protected core, open periphery, automatic conversion — is now standard open-core practice;
we did not invent it, we measured it and followed it.ENGINEER FAQ — what breaks when X goes down, answered from the architecture
Every answer below is a property of the design, checkable in the source — not a
promise. Where the honest answer is "that hurts today," it says so, with the mitigation's state.
| failure | what actually happens |
|---|---|
| GitHub Pages goes down | The pages are static files with no build step — any host serves them unchanged, and every clone of the public repo IS a complete copy of the estate. Your browser keeps working on whatever it already loaded (chain reads are client-side). Honest debt: Pages is the bootstrap crutch, named on this page; the mirror lane + AR/ANT anchors (gate AT-2) are the exit, and until they land, discovery — not function — is what an outage costs. |
| the GitHub org is deleted | Git is the medium: every clone carries full history, and the mirror manifest publishes sha256es of the evidence corpus, so any copy can prove it is the real one. The corpus, specs and receipts are AGPL — legally re-hostable by anyone the moment we cannot. |
| a VPS / relay disappears | By doctrine any server you find behind a feature is a temporary bootstrap and holds nothing unique: state lives in the repo, on chains, or in your browser's own storage. The bSky/Nostr relays are the last planned migration — once anchored to chains/ANT/AR, redeploying relays is autonomous. Until then a relay outage mutes the social echo, never the record. |
| an RPC endpoint dies (Base/ETH/Arbitrum/Vaulta) | Every chain-reading surface carries multi-host failover (two EVM hosts per chain;
three Vaulta hosts), and when all hosts fail the surface renders a failure, never a zero
— the uniform law you can grep for. Any reader can also repoint one constant at their own
node: the pages are keyless eth_calls, nothing more. |
| Autonomi has an outage — or dies entirely | The layering is the answer: the bzDiD root sits BELOW every adapter and survives the loss of any of them — including ANT — by design. Storage re-routes by the same price-break law that chose it (Arweave beside it, the repo beneath both). What an Autonomi loss would cost is the private-vault convenience and one leg of permanence — never identity, never the record. |
| Arweave stops accepting writes | Same answer mirrored: AR and ANT are two independent permanence legs plus the repo; the manifest's hashes make any surviving copy verifiable. One-leg loss degrades redundancy, not truth. |
| your nodes go down (the farm) | Nodes are yours, on your machine — the network re-replicates chunks around absence, and your DataMaps keep working from any client: retrieval needs the network, not your nodes. Earnings pause; nothing is lost but uptime. |
| the language corpus fails to fetch | Every page falls back to English and says so — the picker's counter reads the
truth (⚙ 0/N) instead of silently anglicizing. A withdrawn tongue stops rendering
estate-wide while its history stays in the file. |
| localStorage is cleared / you switch devices | You lose only preferences (register, tongue, tri-role languages) — by design there are no accounts to lose. Nothing here identifies you; nothing here can strand you. |
| this page lies to you | The standing answer: don't trust these pages either. Every claim links its source; the git history is the audit log; the university teaches the checking. The design goal is not "trust us" — it is maximum verifiability at zero credential cost. |
IF YOU CAME WITH ONE QUESTION — five doors
"show me the Autonomi-era identity idea"
Self-Auth + DiD, implemented: an identity that needs no server's permission and survives the loss of any adapter under it
"show me something beautiful in 10 seconds"
a walking tour of fully on-chain art, read live from two chains, keylessly
"show me something useful to me personally"
every nutrient your body needs, computed for your body, every number cited
"I'm into AI × crypto"
the b4b alpha — the Base-lane application
"teach me to check any of this"
five courses where every lesson ends in a verifiable act on real receipts