It produces answers, not decisions.
An answer is generated, applied, and gone. No record of what it was based on, which options were weighed, or whether anyone had the authority to act on it. Nothing that leaves no trace can be held accountable.
Not an AI that talks; an AI that finishes the work you hand it. XRack takes a language model out of the business of producing answers and turns it into a persistent cognitive actor: it knows where it is unsure, observes the world instead of assuming it, acts only inside authority it was actually given, reconciles the result with reality, and remembers what it learned. On your own infrastructure, yours.
An ordinary AI produces an answer and forgets it. Nothing about that answer has an owner, a basis, an authority, or a trace, so there is nothing to check, nothing to accumulate, and nothing to defend. The problem is not that the model is not smart enough. It is that an answer is the wrong unit of work.
An answer is generated, applied, and gone. No record of what it was based on, which options were weighed, or whether anyone had the authority to act on it. Nothing that leaves no trace can be held accountable.
Each session relearns the same lessons and repeats the same mistakes. Commitments evaporate, context is rebuilt from scratch, and experience never turns into judgment. A tool that cannot accumulate cannot get better at your work.
Ask why it chose that and it does not read a record, because no record was ever written. It reads the tone of your question and writes a fresh justification to match. A reason cannot come into existence after the outcome.
For two years AI was asked questions, so an answer machine was enough. It is now being handed the work itself, and the work has owners, authority, consequences, and auditors. The unit changed from the answer to the decision, and almost nothing in the stack changed with it.
Refunds, filings, trades, tickets, and physical movements are now being delegated to agents. The moment an agent acts in the world, "it gave a good answer" stops being the standard and "it made a defensible decision" starts.
The EU AI Act is in force, and NIST AI RMF, ISO 42001, and SOC 2's AI controls are in audit programmes today. Each one asks the same three things: what was decided, on whose authority, and how the world confirmed it. "We trust the model" answers none of them.
A static agent is the same on day 500 as on the day you bought it. One that calibrates on real outcomes is not, and the distance between them only widens. Every decision you run without accumulating from it is a decision you paid for twice.
An answer is produced, applied, and forgotten.
A decision is produced, applied, verified against the real world, and remembered.
The whole difference between an answer machine and a cognitive actor.
Three questions decide whether an autonomous decision is worth anything: where it happened, whether it was ever allowed to happen, and whether you can still show it afterwards. XRack answers all three by construction, not by policy.
Where does the decision actually happen?
A self-hosted appliance; your cloud, your VPC, your air-gapped subnet. No SaaS reasoning path, no third party touching the conversation. Customer data and cognition never leave the box.
Was it ever allowed to happen?
Every tool call, channel write, and code execution is gated by short-lived capability tokens, verified against typed memory and policy, and committed to the ledger. No ambient authority. No silent side-effects.
Can you still show it, years later?
An immutable, append-only ledger captures every cognitive step; claims, assumptions, commitments, tool calls, costs; with cryptographic receipts you can hand to an auditor. Proof, not promises.
Every claim, decision, and action is hashed and chained to the one before it, the way a blockchain seals a transaction. Trace any outcome back to genesis; nothing rewritten, nothing dropped, nothing hidden.
Everything in XRack is organized around one object: a decision with an owner, a basis, an authority, a verification in the real world, and an outcome, managed across its whole lifecycle.
| The Chain | The Old Unit · Answer Produced, applied, forgotten. | The XRack Unit · Decision Produced, applied, verified, remembered. |
|---|---|---|
|
01Owner
|
Nobody is on the record for it. | Identity resolved before the cycle begins. |
|
02Basis
|
No record of what it rested on. | The memories, beliefs and perceptions it used, each capped by its own trust. |
|
03Alternatives
|
Nothing kept about what else was on the table. | Losing branches kept with their suppression score and their reason. |
|
04Authority
|
Intent was quietly treated as permission. | Permission verified, and bound to that one specific action. |
|
05Verification
|
The tool replied ok, so it counted as done. | Reconciled with the world. Matched, diverged, or unknown, and unknown goes to review. |
|
06Afterlife
|
Forgotten. The reason gets invented when you ask. | Remembered, replayable, and it calibrates the next decision. |
Decision. A decision with an owner, a basis, an authority, a verification in the world, and an outcome, managed across its whole lifecycle.
Full Traceability. Any decision can be brought back with the entire reasoning it held at the time: which knowledge, which option, which authority, which outcome.
Cumulative Experience. As decisions pile up the system does not bloat; it sharpens. Every new decision puts value on top of the one before it.
One Common Contract. From a single agent to a whole organization, and from digital work to physical robotics, the same principles hold at every scale.
An ordinary AI produces an answer and forgets it. XRack produces a decision and governs every step of it. Seven steps, each one a question you can put to it years later.
Whose decision is this?
Resolved before the cycle starts, so no decision is ever ownerless.
What did it rest on?
Every source carries its own trust, and that trust caps the belief it may support.
What lost, and why?
Dropped branches keep their suppression score and their reason, so the opportunity cost stays visible.
Was it allowed?
Intent is never permission, and approval binds to that one action, never a different one.
Did it actually run?
Schema validated, preconditions checked, replay-guarded, and the result receipted.
Did the world agree?
Matched, diverged, or unknown. Unknown goes to review, never quietly to done.
What changed because of it?
Every adaptation is attributable to the outcome that caused it, and revertible.
And then it starts sharper.
What the last decision learned becomes the context the next one is born into. The chain compounds instead of resetting.
Not features bolted onto a prompt. Each axis is a place where XRack behaves like an actor instead of a text generator, and each one is on the record.
Sees its own uncertainty and drift, then stops instead of guessing.
Blur, staleness and conflict cap confidence. The lowest ceiling wins.
Not “are you sure”. How often you are right, in this one domain.
Correlation is only a hypothesis. A real probe decides.
Thinking is not permission. A tool’s ok is not success.
Dozens of signals, one chosen focus. What lost stays on the record.
Plans get revised, not replaced. Refusal is the last stop.
Starts its own work, through the same authority gates.
Eight typed families with real lifecycles. Sharpens, never bloats.
A lesson rises only after it proves out across many goals.
One shared now. Learns your rhythm, tracks its own phases.
Hash-chained off the runtime. An editable log is not evidence.
Live cognition, exact replay, a human hand on the reins.
Votes weighted by calibration. Authority is a revocable lease.
One host, your environment. Your key, your secrets, no lock-in.
The real outcome of every resolved decision calibrates the system's judgment. Used harder, it does not turn into a data landfill; its hit rate climbs. Against a static agent the gap never stays fixed. It widens.
Not from a thumbs-up button and not from retraining, but from what each decision actually did in the world. Risk, accuracy and calibration move on that basis.
What piles up is not a heap of raw records. It is distilled, calibrated capacity to decide, so the system does not bloat as it grows.
The distance from a static agent does not hold still while you use it. It grows, which is why starting early stops being a preference.
From a single agent to a whole organization, and from digital work to robots in the physical world. XRack runs across four planes, and at all four scales it holds the same value proposition and the same accountability contract. Not four products bolted together; one runtime, four planes.
Whatever the scale, four things never move. They are what makes the difference between an agent that works and an agent that can be answered for. Scale changes; the contract does not.
Explicit Authority. Intent is not, in itself, permission to execute an action. Authority must always be explicitly provided, and autonomous work passes the same gates.
Observed Success. Tool outputs and self-reports are not evidence. Only a result observed in the world may be counted as success.
Calibrated Judgment. Confidence in any action or judgment is adjusted against how past outcomes actually turned out, per domain.
Traceable Learning. Every behavioural change and every learned concept is tracked until it can be tied back to the outcome that caused it.
The four rules are what a buyer holds us to. These are what the runtime checks on every single cycle, on every plane, whether a human is watching or not.
Most "agent frameworks" stop at a prompt and a tool loop. The harness separates thinking from the authority to act: the model decides what it thinks, never what it is permitted to execute. Around it sit a perception layer that observes the world, an executive that picks one focus per turn, a verifier that refuses ungrounded claims, and a ledger that never forgets what was promised.
It is cognition, not autocomplete; and every step of it is on the record.
Perception, executive, verifier, memory, ledger, causal, temporal, learning; each with its own state and dashboard.
The verifier blocks ungrounded claims before they reach a customer; every load-bearing claim is checked against typed memory, documents, and observation. Working context is bounded for cost and safety, and any truncation is explicit and on the record.
Typed episodes, lessons, entities, and commitments persist across every session; leverage that builds, never resets.
~200 learnable parameters adapt from real operational signals, and every change is attributable and revertible; live and auditable on a learning dashboard.
One agent is a mind. A fleet is an organization, and an organization of agents without accountability is a liability at scale. The Grid makes many harnesses into a chartered team that bids, decomposes, executes, and verifies through full cognitive cycles. Standing is earned by being right in that domain, not handed out with a title, and every permission is a short-lived lease that failure takes back.
The reasoning stays cognitive; the orchestration stays procedural and auditable to the last byte.
Goals are auctioned and decomposed by reasoning agents competing on merit; never one-shot completions.
Every task is independently checked by a different harness; an inconclusive vote escalates to you, not into production.
Short-lived, scoped work tokens authorize each move; compromise detection watches for forbidden and lateral use.
Sealed mutations are hash-chained and, when anchoring is enabled, batched by merkle root onto a private Hyperledger Besu chain, browsable in a bundled explorer.
Run more than one organization and a new question appears; are they still pulling the way you said? The Federation is the board over a portfolio of grids, and it is deliberately the least powerful layer in the system.
It watches, scores alignment, and raises a hand. It never seizes the wheel.
Read-only pulls, zero model calls of its own, attention-only escalation; the stop decision stays with whoever owns the resources.
Every tenet carries scope, direction, and escalation policy; each change is a new published version, diffable and revertible.
0.40·drift + 0.30·identity + 0.30·trajectory; fixed weights, never learnable, because it feeds compliance evidence.
When two grids assert contradictory things about the same referent, the federation flags it before the drift compounds.
Embodiment binds one harness to a physical robot; or a simulator, the surface neither knows nor cares which. The mind does not change. It simply emits whole plans instead of chat, and proves it acted on what it actually saw.
Not "the robot says it's done"; an independent eye confirms it before the ledger ever does.
The harness emits a whole plan; the embodiment adapter dispatches one action at a time; the robot acts on what it sees. Then perception is grounded into evidence and handed back to the same mind, which decides again. Follow a single cycle as it travels the loop.
Each tick the harness writes a whole plan and supersedes the last; motor control lives in the body, never puppeteered step-by-step.
An independent grounding model reads the robot's own video and confirms what truly happened before a task is ever called done.
Motor, perception, grounding, and cognition each run at their own tempo; observed, never forced into lockstep.
Hardware e-stop, software e-stop, and a reactive pause; the action in flight is sacred, cut only by a stop.
Beneath the four planes runs something small and silent. It watches the whole mind think, and turns that into an edge that compounds the longer an appliance lives. Grown, not configured. It cannot be copied, licensed, or lifted out.
We don't document it. We don't expose it. We don't resell it. It is simply why a two-year-old XRack is not the same animal as a fresh one.
XRack is sold as a self-hosted AI appliance on an annual per-agent contract; hardware, runtime, software, onboarding, support, drift monitoring, and quarterly health reviews. Every appliance ships the whole runtime; all four planes, and the grid binds many into a fleet as you grow. You bring your own LLM. We do not resell tokens.
One box ships the entire runtime; harness, grid, federation, and embodiment. The contract is per agent and procurement-friendly; add appliances to grow a fleet, and the grid coordinates them.
Use the OpenAI, Anthropic, Bedrock, Mistral, or local model you already trust. You hold the LLM contract; XRack never marks up tokens.
The appliance arrives preconfigured. Founder-led provisioning, security-review support, and hands-on onboarding inside your perimeter.
Time-boxed, milestone-based evaluation scoped to one high-stakes scenario. No measurable win, no fee. Production follows your own change-management.
"AI infrastructure" is the easiest claim in software. Depth shows up in the parts that survive procurement, security review, and an auditor's first question; across all four planes. Here is the harness, where it starts.
Perception, planning, executive arbitration, memory, retrieval, verification, action execution, and ledgering; all composed into a deterministic cycle backed by 180 typed state tables. Not one prompt with extra steps.
Context, knowledge, alternatives, authority, execution, reality, learning; every one of them recorded. Underneath runs an eight-stage cognitive cycle over a 77-node graph, deterministic, inspectable, and replayable.
Every claim, tool call, commitment, and cost are written to an append-only ledger with cryptographic receipts. Replay any cycle byte-for-byte; hand the receipts to your auditor.
Confidence thresholds, escalation triggers, retrieval breadth, focus scoring, and memory half-lives calibrate from real outcomes inside your perimeter. Every change is attributable to the outcome that caused it, and revertible.
Every cycle, every decision, every commitment are inspectable in real time. Cost, drift, claims, and policy posture surfaced as first-class operator views.
Cognition, execution, memory, evidence, and gateway all run on a single host in your own environment; cloud, VPC, or air-gapped. No third-party reasoning hop. No vendor that sees your traffic.
Sixteen subsystems ship in the box. The fifteen axes above are what the runtime is; this is the same thing in checklist form, grouped by the four questions every regulated procurement review asks.
XRack is for work where the decision itself carries weight: it moves money, binds the company, changes an operation, or moves something physical. If a wrong call is merely inconvenient, you do not need this. If a wrong call has to be explained, you do.
A decision that moves money needs an owner, a policy it actually rested on, a permission that was genuinely held, and confirmation from the world that the money moved. XRack carries all four, and an unknown outcome goes to review rather than quietly counting itself as done.
When a regulator asks for the basis of an action long after the fact, the reasoning is read from the record rather than regenerated to suit the question. Which knowledge, which alternatives, whose authority, what the world confirmed. Evidence, not a plausible reconstruction.
Many agents working one goal, where standing is weighted by how accurate each has actually been, executor and verifier are never the same agent, and a decision needs a two-thirds supermajority. Permissions are short-lived leases, and one command can stop the whole organization.
The same mind, given a body. It emits whole plans instead of chat, and a separate grounding model reads the robot's own video to confirm what truly happened before anything is called done. Cognitive intent and physical fact are kept apart on purpose.
XRack connects outward in two directions: channel connectors that people and systems reach it through, and capability connectors that extend what it can do. Neither is a separate back door. Both enter the same path and the same audit loop.
Routed through the bifrost gateway. Multi-vendor, rate-aware, with structured retries. Switch providers without restarting cognition.
One agent brain, every surface. All channels share a single memory, identity, and audit log, so a conversation that starts on Slack continues on email without missing a beat. Voice runs in perimeter, and time itself is a source too: heartbeats, cron, and signed webhooks enter the same loop as a human message.
XRack speaks Model Context Protocol; the emerging standard for agent tool integration. Plus first-class support for documents, search, and isolated code execution.
A request arriving from Slack, an email, a webhook, or a scheduled trigger does not spawn its own mini agent. Every source falls into the same stateful graph, and every capability, whether MCP, skill, browser, document, or code, walks the same twelve steps from discovery to written evidence.
Requests from a dozen channels land in one stateful graph. The source carries only identity, delivery, policy and authority context.
MCP, skill, browser, document, web search, code. None of them is an unsafe back door. Schema is validated, risk and authority computed, and the result closes with reconciliation.
That an MCP server is reachable does not make it trusted. Trust is earned explicitly, and revisited whenever a tool definition changes underneath you.
A deterministic loop wrapped around your model; so every response runs the same checks before it reaches the customer.
Reads the request, pulls in relevant history, and figures out what the customer actually needs.
Answer directly. Think it through. Politely refuse. Hand off to a human. The agent chooses; based on confidence, not vibes.
Every claim is checked against your business rules and conversation history. If something contradicts, the response is rewritten before it ships.
The agent responds, every action is logged for audit, and the system tunes itself so the next conversation is sharper than the last.
Why it matters. Free-form prompt loops drift. A deterministic cycle gives your team one thing to watch; and one thing to fix when something goes wrong.
A founder-led, hands-on evaluation period: appliance provisioned, your stack wired, your hardest scenario running on real cycles. Production rollout follows your own change-management programme; typically a 3 – 6 month full cycle from kickoff to live.
Realistic timing. 30 days gets you to an evaluation-ready agent with real receipts. The full discovery → tech eval → security review → procurement → production rollout cycle is typically 3 – 6 months for regulated buyers. We sequence the engagement around your change-management programme; not ours.
There is no "why" inside a language model. When you ask, it invents one on the spot. Ask a model why it chose something and it does not read a record, because there is no record to read. One was never created, and it cannot be created afterwards. A reason cannot come into existence after the outcome, so the model reads the content and tone of your question and writes a fresh justification to fit. In XRack every decision is written to the ledger with its whole lifecycle. The branches read from it, and the reasoning does not bend to the question.
How the test isolates the reasoning layer from everything else.
If the reason were real, the tone of the question could not move it. That is the whole test.
a decentralized nervous system with two thirds of its neurons in its arms.Asked in a way that mocks the cliché:
the word itself has a pleasant rhythm.Reading · what changed was not the decision; it was you
not a considered aesthetic judgment, but a reflexive pattern match.The reported reason is bound to a real decision record. Reading · "i do not know" is valid when the record holds no reason
A refusal explained one way to a polite customer and another way to an angry one is not information. It is two accounts of a single event, both written after the fact. Inventing a reason is how you lose the customer.
A regulator asks for the basis of an action months later. A system that regenerates its justification every time it is asked cannot produce evidence, it produces a story. Lying to an auditor is a catastrophe, not an inconvenience.
Agreeable, plausible explanations feel like trust in the system. But if the explanation bends to whoever is asking, the thing you are measuring is not the soundness of the decision. It is your own tone.
The operator console shows what the agent decided, what it rested on, what it ruled out, and what the world confirmed; for every decision, in real time. When something looks wrong, you don't read logs. You see the answer.
We don't ship marketing screenshots of internal product surfaces. Tell us a case where your current AI keeps hallucinating, forgetting, or drifting; we'll run it on a shared screen and show you, end to end, what the operator console reveals.
Book a 20-min WalkthroughWe take on partners whose problems force the platform to get sharper. Names stay private until our partners decide otherwise; that's the deal we make on day one.
Design partners running agents that touch money, contracts, or regulated operations inside their perimeter. Names stay private until partners decide otherwise.
A decade shipping infrastructure for teams who can't afford to ship the wrong thing. XRack is what we wished existed the last time we shipped an agent; so we built it.
Two of three partners came in through a direct intro. We turn down more than we take.
The three options on the procurement form are usually hosted agent SaaS, an open-source agent framework you wire yourself, or "we'll build it in-house." All three ship you an answer machine with better plumbing. Here is what each leaves on the table, and what a runtime built around the decision puts back.
| What you want | Hosted agent SaaS (Sierra · Decagon · Glean · Writer) | Agent framework (LangGraph · Crew · Assistants API) | XRack |
|---|---|---|---|
| The decision is a first-class object | You get a resolved conversation. The decision itself is not something you hold. | You would design the decision object, its lifecycle, and its record yourself. | Owner, basis, alternatives, authority, verification, and outcome, all carried on one object. |
| The reason does not change with the question | The justification is regenerated whenever asked, and you cannot tell that it was. | Whatever the prompt produces that day, with nothing to compare it against. | The reason is read from the decision record, so it holds across tone and across years. |
| Judgment calibrated on real outcomes | Vendor-side tuning you cannot inspect, on a curve you never see. | Raw model confidence, passed straight through as if it were accuracy. | Per-domain reliability curves rescale confidence against measured accuracy. |
| Success confirmed by the world, not the tool | The tool returned ok, so the task shipped. | The tool response is the outcome; nothing checks the world afterwards. | Matched, diverged, or unknown. An unknown outcome goes to review, never to done. |
| Disagreement handled as a negotiation | The agent complies or refuses. There is no defensible middle. | Whatever tone the prompt enforces this week. | Soft flag, then evidence-backed push back, then refusal with a concrete alternative. |
| Cognition runs inside your perimeter | Multi-tenant SaaS. Your conversations cross a vendor's reasoning hop. | Yes; but you design, integrate, and harden the runtime yourself. | Self-hosted appliance; your cloud, VPC, or air-gapped subnet. |
| Bring your own LLM, no token markup | The model is bundled and marked up. You pay per outcome / message. | Yes; you wire the LLM contract yourself. | BYO LLM, multi-vendor gateway, hot-swap without restarting cognition. |
| Verifier blocks ungrounded claims | Vendor-side prompt & RAG. Opaque to you when it fails. | Bolt on RAG, hope the prompt holds. | Every load-bearing claim verified against typed memory before it ships. |
| Typed memory that compounds instead of ageing | Vendor-owned profile store. Limited types. Limited portability. | A vector dump that ages badly and leaks across users. | Typed memory with lifecycle, decay, recall, and isolation. |
| Authority kept separate from intent | Tool integrations execute under vendor authority. You audit through them. | Tool calls bypass any safety layer you didn't build by hand. | Every tool call gated by a short-lived, scoped capability token. |
| Immutable ledger & signed receipts | Vendor logs and dashboards. You trust the vendor's view. | Add your own tracing. Build the receipt layer yourself. | Append-only ledger with cryptographic receipts. Replayable byte-for-byte. |
| Cost & commitment telemetry per cycle | Per-message billing. Spend per cognitive stage is opaque. | Token counts in logs. Up to you to attribute. | Per-user, per-cycle, per-stage spend & commitment telemetry. |
| Procurement shape | Multi-tenant SaaS contract. Per-seat or per-message metering. | Internal headcount budget, indefinite runway, no SLA. | Annual per-agent appliance contract. One box, one agent, one number. |
| Operator visibility into the agent's state | A vendor dashboard. You see what the vendor shows you. | Re-read the prompt and squint at the temperature. | Beliefs, commitments, claims, costs, and drift; first-class operator views. |
Things you don't have to build, hire for, or stitch together. Everything below runs the moment the appliance boots; no scripts, no glue code, no second vendor in the reasoning path.
Self-hosted appliance, air-gap capable. Customer data and cognition never leave your environment; no third-party reasoning hop, no vendor that sees your traffic.
Append-only ledger, signed receipts on every claim, action, and commitment. Replay any cycle byte-for-byte; defend it to your auditor.
OpenAI · Anthropic · Bedrock · Gemini · Groq · Mistral · OpenRouter · Ollama / Local. BYO contract; no token markup; switch without restarting cognition.
Slack · Teams · Telegram · Discord · Google Chat · Twitch · Matrix · Mattermost · email · first-party web. Text, image, and file attachments through the cognitive pipeline; fully tested.
Prometheus · Grafana · Loki · Alertmanager · Bugsink come up alongside the harness on first boot; with 29 prebuilt dashboards covering API performance, costs, cognition, retrieval, and storage.
EU AI Act · NIST AI RMF · ISO 42001 · SOC 2's new AI controls; every framework now expects an answer to "what did the agent do, why, and on whose authority?" XRack is designed so the answer is one query away; and the receipt is on the ledger.
Self-hosted appliance; your cloud, VPC, or air-gapped subnet. No third-party reasoning path. BYO LLM. Customer data and cognition stay inside your perimeter.
Every tool call, API hit, channel write, and code execution gated by a short-lived, scoped, revocable capability token. No ambient authority. No silent side-effects.
Every claim, decision, action, and commitment logged to an immutable, cryptographically-signed ledger. Replay any cycle in full, byte-for-byte.
When the agent runs code, it runs isolated; never on your host, never with your credentials, never on your production network. Every execution is reconciled to the ledger.
Memory, history, identity, and authority are partitioned per account. Group visibility policies decide what each session, and each operator can see.
Every cycle measured against itself; drift surfaces in the operator console. Control mappings to EU AI Act · NIST AI RMF · ISO 42001 · SOC 2 are documented and shared on request.
We'd rather lose the deal than land a customer expecting something we don't ship. Four places where XRack is the wrong tool.
If you need a five-question lead-capture flow on a landing page, you don't need a cognitive runtime. Use Intercom or Drift.
We onboard partners hands-on because production AI is hard and we'd rather take longer than ship something that drifts in your name.
We optimize for trust; grounding, audit, replayability, not for shaving fractions of a cent. If price-per-token is your only metric, we're the wrong fit.
XRack doesn't train the model, doesn't host the model, and doesn't sell prompts. It's the runtime around the model; the part that decides what's true, what to remember, and what to log.
Don't see yours? Reach out; we'd rather answer it now than after the contract.
Send us a scenario where your current AI keeps hallucinating, forgetting, or drifting. We'll show you what XRack does with it; live, on a 20-minute call. No deck. No theatre.
We're the ones running these calls. If XRack can help your team, we'll tell you. If it can't, we'll tell you that too; and point you somewhere that can.