the neutral layer where agents, tools & memory run together

The baseplate where
intelligence composes.

A small, restartable core with defined connection rules. MCP tools, A2A agents, SKILL.md skills, and the components no standard covers — memory, workflows, surfaces — plug in, combine, and can be removed without the system going down. We adopt the standards; we build the layer that runs them safely.

scroll
the gap

The protocols exist.
What's missing is what runs them safely.

MCP, A2A, SKILL.md and the rest define how agents and tools talk. No one ships the layer that makes a heterogeneous system of them safe to run together — contained, guarded, health-checked, and restartable on one machine.

✕ today

Standards define the language

MCP (tools), A2A (agent-to-agent), SKILL.md (skills) — open and consortium-governed. They specify messages.

  • Components hang off someone else's product — or a stack of them
  • Nothing contains a hostile or broken component
  • Your data lives inside their centers
  • No shared enforcement of who may do what
✓ what we add

We build the enforcement layer

A neutral core that is not an agent, not a vendor, not a product — it runs the protocols with teeth.

  • MCP tools, A2A agents, SKILL.md skills — they all plug in
  • One containment group per component — a crash stays local
  • Your data stays in your components — the core holds none
  • Scoped grants, expiry, revocation — enforced, not declared
what we build

One core. Nothing else lives in it.

agents
memory
tools
workflows
surfaces
your component
connect · via adopted standards · scoped
the core
routes signals guards permission tracks who is alive

Function is the combination. The core does not think, remember, or act — it lets things that do, do so safely, whatever standard they speak.

01

It routes

Signals cross the core with deadlines and delivery semantics. Components speak their own standards — the core connects them without owning any.

02

It guards

Every connection carries a scope — what this component may read, do, and reach. The guard enforces grants, expiry, revocation, and the core's delegation law: authority passed on can only shrink. Delegation is not an add-on — it is enforced here, in the core.

03

It tracks life

Which components are registered, healthy, degraded — and when something must be treated as gone.

  no component code   no models — local or remote   no content, no keys   no outbound network   routing · guarding · life — only
what we adopt · what we create

MCP and A2A define how agents talk.
We add what nobody else ships.

We adopt the open standards — and we build the pieces no standard covers: the missing protocols, the sovereign world, and the layer that runs everything safely on one machine.

adoptMCP · A2A · SKILL.mdtools, agents and skills speak the community-governed standards
adoptCDP · Wayland · JSON-RPCbrowsers, displays and chains connect through their native interfaces
createthe missing protocolsmemory · durable runs · workspace embedding · signing ceremony
createthe sovereign layerprivate worlds · shared worlds by agreement · evidence of what happened
01

The memory protocol

No cross-vendor, owner-controlled memory standard exists. We publish one: read, write, search, update, expire, snapshot — with declared durability and evidence roles. MCP's resources are read-only; memory that outlives sessions needs a real protocol.

02

Durable runs & the consequence protocol

Runs that survive their process — and irreversible actions that persist intent, expose unknown outcomes, and reconcile reality before retrying. No duplicate payments, publishes or sends.

03

The sovereign world

One machine, many principals: each gets a private world no one else can read. Shared worlds exist only by agreement, with roles and quorum. Nobody has ever shipped this for agent systems.

04

The evidence spine

Every consequential action leaves a record you can read: who allowed it, what it touched, what happened — with observed facts kept apart from agent reasoning. "Why did you do that?" is answered from the log, not guessed by the model.

05

Delegation that can only shrink

One agent can hand a bounded slice of its authority to another — scoped, with an expiry, a purpose, and a depth limit — but the receiver never gets more than the giver holds. Revoke the grant and the whole chain dies at the next check. Swarms can form; they can never out-power their principal.

Extensions to adopted standards are additive and optional — unmodified community artifacts keep working. Everything we create is a public, versioned spec; the baseplate is what lets a heterogeneous system — different standards, different vendors, different models — run on one machine without breaking each other.

the rule-set

The value is in the rules,
not in what plugs in.

rule 01

Anything can connect

If it speaks a standard — MCP, A2A, SKILL.md, or one of ours — it joins, from any author, now or in ten years.

rule 02

Nothing connects silently

Every component declares what it does and what it needs. The core grants a subset — nothing more.

rule 03

Everything can be removed

Removal is a legal operation. The core keeps routing; only that component's connection stops.

rule 04

Nothing takes the system down

One broken or hostile component fails alone — one containment group per component, bounded resources.

the guarantee

The system does not flinch.
Because nothing else can fall.

momentA component breakscrashes, hangs, or turns hostile mid-run
resultOnly it goes downone containment group · the rest keep routing
worst caseThe core itself is killedcrash · power loss · deliberate attack
restartIt comes back wholestate reloads from durable records · grants reload · components reconnect

The guarantee is structural: the core holds no content and no component logic, so it has nothing that can corrupt the combination. Continuity is preserved by what the core does not contain.

the proof

We don't ask you to believe.
We crash it on purpose.

built
person A
private world
agent · memory · values
built
person B
private world
agent · memory · values
shared
one shared world
a task both approve
joint action needs both · no path between privates
attack
deliberate kill
core · agent · memory
mid-task, mid-request
restore
everything reconnects
state · grants · task resumes
no widening · no duplicates · worlds intact

If it cannot survive that and hand every private world back exactly as it was — it does not ship. This is the acceptance test of Phase 3.

why this is the moment

Every computing wave ends
on a neutral layer.

the PCThe OS became neutralhardware from everyone
the webThe protocol became neutralbrowsers from everyone
appsThe store became neutralbuilders from everyone
intelligenceThe enforcement layer becomes neutralstandards exist — the safe place to run them doesn't

Combinations are built by many independent suppliers, not by the platform owner. The neutral layer — not the best product — is where the ecosystem settles. That layer is what we build.

the relationship

ResonantOS is a ResonantDAO project.

The baseplate is the technology.
The DAO is the community around it.

→ resonantdao.com
resonantos
  • the neutral baseplate
  • routing, permission, life
  • components plug in and out
  • proven by deliberate failure
resonantdao
  • the community of communities
  • membership, contribution, stewardship
  • the economy built on contribution
  • governed by people, not capital

The architecture is designed and built in the open — with the community that will steward it. The full DAO design (credentials, economy, governance, roadmap) is in the ResonantDAO whitepaper.

join the build

The baseplate is designed on paper.
Now it needs hands that attack it.

Before one line of code ships, we want the strongest minds on the rules, the core boundary, and the guarantee. Build and test with us — the architecture is discussed in the open, the tech team is forming now.

discord · resonantdao · augmentatism — the whole stack, one community