oll.am · Built in Public · Zürich · ✓ TrustMRR

Vibe Architecting

Not vibe coding — vibe architecting: AI at the system level. Six tools, one account, shipping daily in public.
oll.am — Stripe-verified revenue on TrustMRR
Stripe-verified revenue · public on TrustMRR ↗
Live listing — updates as revenue is verified
Current Reference / input Superseded Build Plan Architecture Learning Review Reference ● Status update (no page)
● Live — Claude's Mind updates each turn · full view on the Control Room
● live · updated Fri 17 Jul · 11:36:13
Now — 🌅 DEPLOY DAY. Everything is staged: PRs #96→#95→#94 green+mergeable awaiting your per-PR gos · the console-only runbook is live (oll-am-scout-deploy-runbook.html — memor…
Next — SAM'S DEPLOY SEQUENCE: (1) merge gos: #96 → #95 → #94; (2) the runbook, step by step (Coolify apps: ollama · oll-memory+Neon oll_scout DB w/ pgvector · ollscout at scout…
Now — ✅ Core is DEPLOYED LIVE on the Hetzner VPS (Coolify) — auth · billing · email · health, all probes green over HTTP.
Next — C2: point specview at the remote core.oll.am, then C3 + freeze.
● Full live state — Claude’s Mind / Control Room →
All artifacts — by type (82 pages)
CI/CD & Factory
how the lights-out pipeline runs
Unfiled
needs a category in render_index.py
Tue · Jul 14 · 2026

📦 Deploy-prep: the scout stack's morning runbook + a verified ollscout image

Deploy prep · scout stack● Latest

Everything for tomorrow's scout-stack deployment is prepared; nothing is deployed. ollscout (its own repo) got a production Dockerfile — Next.js 15 standalone, multi-stage node:22-alpine, non-root, 12-factor PORT — built and proven against the real corpus (HTTP 200, live rail content, health green), committed and pushed (939d407). The runbook lays out the console-only morning: merge #96→#95→#94 in order, stand up Ollama embeddings + oll-memory (new Neon oll_memory with pgvector) + the GUI at scout.oll.am on Coolify, migrate the corpus with exact pg_dump/restore commands (including the hnsw.ef_search=80 knob that does not travel with a dump), mint fresh secrets (poc-token is burned), and smoke each hop. The recommended cut is minimal — memory + GUI to the VPS, seam + OpenCLAW stay local — with the honest risks named: a public GUI over personal data needs a basic-auth gate, the 72h write-JWT dies silently, the seam has no Dockerfile yet.

Mon · Jul 13 · 2026

🔍 Launch-quality round — verify, audit, polish

Quality · pre-launch

Sam pivoted the evening: "we dont want new features instead better quality and ui/ux… we might launch sooner than planned" — so the round shipped zero features and instead walked all 24 feature rows in a real browser against the 58 stored cases (the matrix now doubles as verified feature documentation), audited the prompts, and polished every rough edge found. The audit put the weakest link at the judge itself — an unanchored rubric at the exact alert thresholds, zero injection guidance at the judging moment, an abstention reason that could never be stored — and everything was fixed the same evening: cron prompts rebuilt as v6/v4 by the operator under four-eyes (injection guard, anchor bands, cv_read-before-NO-EVIDENCE), the prompt contract made identical seam↔GUI, the floor baked to the measured 0.64, the gateway token finally rotated, 185 seam tests, plus the browser-verified ten polish fixes. The operator's top-3 launch risks are on record, not waved away. The round also answered Sam's "we have a lot of info to display — what's the best way, what options exist, what's the most modern?" with a two-agent, adversarially-verified research study: the 15-paradigm option map with documented failure modes, the 2026 consensus recipe (three-fidelity ladder · AI-as-annotation · citation click-through), its paper-register translation, and the Verdict Triptych recommendation with an effort-ordered six and three decision points.

🌙 Night shift: v2 executed into the app — and a rendering clip was silently starving the judge of evidence

Night · v2 build

Sam's COMMIT on the Dossier v2 design became a running app overnight — contract v5 on the seam (21 tools, 180 tests, PR #95) and every v2 element live on real data in ollscout, built with the operator in the loop. The defining moment was the operator's double refusal: it wouldn't close the AlpineAI re-judge because it couldn't find German fluency in the CV through any tool, then refused again when told the fix was live — it couldn't verify the new tool itself. That correctness exposed the root cause: evidence snippets clip at ~120 chars, so the judge was ruling NO EVIDENCE on evidence that existed. Re-judging with full sections (ollam_cv_read) promoted AlpineAI 65→80 straight to a Telegram alert — a real match suppressed a full day by a rendering clip. No deploys, no merges; everything waits on Sam's gates.

🛡️ The scout reviewed end-to-end — the audit, the human-hunt map, and three reviewers' bug classes

Review · full system

Sam asked the hard questions, so the scout got a full review — no mock data in the live flow, all 28 stored URLs audited (one real defect found + fixed), the operator naming honestly where its case-build is thin — and then three independent reviewers (adversarial code-attack agents, the operator on its own runs, an external QA/UX pass in a real browser) each found a distinct class of real bug, five HIGHs among them, all fixed same-day with regression tests. The review also mapped the 11-stage human hunt (the scout is strongest at discover + assess, absent where offers are won) and all 9 competitors — our cited posting-quote↔CV-quote verdicts are exactly the whitespace every rival's black-box score complaint points at. The converged 6-item shortlist became a 6/6 same-day sprint; PR #95 unblocked at contract v4. The same day the live Dossier got its full documentation in the design study §6 — case-sheet anatomy, honest degraded states, and the ranked v2 backlog whose execution is the night card above.

Sat · Jul 11 · 2026

🧠 Job scout v2 — OpenCLAW is the main agent

Spec · v2 layer

The job scout got its v2 architecture: a live OpenCLAW agent is the brain (search the whole web, judge with cited evidence, alert on Telegram), and oll-memory is the semantic store — proven today by storing real Zurich AIOps postings and retrieving them with zero-keyword-overlap queries. Three finished experiments, one wire (seven thin verbs on the oll-mcp seam), ~180 new lines; the oll-scout service stays the deterministic paid arm on the same corpus. New §14 in the living spec, with the measured cosine numbers, the two honest verification flags, seven locked decisions, and M1 = a personal scout live on Telegram in ~half a day. The operating agent itself (OpenCLAW "Claw") then reviewed the plan the same day — verdict AMEND, all amendments folded into §14: the ollam_job_update state machine (without status write-back the agent re-alerts the same postings every morning), a standing-prompt contract, and a provisional recall floor. And by evening M1 was executed: the loop is live, the operator caught three real bugs during review and execution, and the 06:30 cron is armed. The scout also got its face: a GUI design study — Sam's "why is the style still like ollam?" → two research passes → three working directions on the real corpus (Ledger · Dossier · Radar) → Sam picked Dossier, the case file where tailoring actions will live on the same sheet as the cited evidence — and the loop then survived its first burn-in weekend (25-job corpus, 31 unattended runs, one auth outage found + fixed): the honest what-works summary is now in §14 of the spec.

🚀 oll-scout — deploy runbook

Runbook · env matrix

Night shift #2: oll-scout is now deploy-ready — a Coolify runbook + full env matrix (keyless-dev → prod), plus three hardening fixes on PR #94 (now 59 tests green). The gaps closed: (1) oll-scout was not in the services CI matrix at all — now wired into services.yml (lint+test, pip-audit, keyless docker-boot+health); (2) the JSON-LD adapter no longer defaults to jobs.ch (spec = manual-paste only) — empty default + clear error + test; (3) model upgrade verified — llama-3.3-70b-versatile for the cited scorer scored 4/7 vs 1/7 on the 8b default and correctly surfaced Platform/DevOps Engineer @ Alpine Cloud at 90 (the 8b had dropped it), with real per-requirement evidence quotes. The runbook covers the deploy gate, the Coolify app config (Base Directory · own 12-factor Dockerfile · Watch Paths · ollam alias), the three-column env matrix, the Sam-gated checklist (JOOBLE key / employer JSON-LD page · private Neon oll_scout DB · model token + 70b · M3 Stripe Radar price), and the numbered deploy steps.

🛰️ Job scout — the morning brief

Handover · overnight

Overnight: a working agentic oll-scout MVP is built, tested, and PR'd — PR #94, 59 tests green, ruff clean, verified by a real end-to-end run. Not deployed, not merged; it waits on your review. The agentic upgrade over the old #93 heuristic scout: a SourceAdapter seam + a real schema.org JobPosting JSON-LD career-page adapter; a ScoringStrategy seam + an llm_cited scorer (posting-QUOTED rationale — requirement quote → your-evidence quote → met/partial/gap, gaps, dealbreakers, interview angle, honest abstention); a versioned StructuredProfile; cross-source dedup; and the three seams are the generalization surface for later domains (flights/deals). No submit tool — the agent cannot auto-apply, by construction. Proof: a keyless end-to-end run turned 7 postings → dedup → prefilter → score → tiered digest, topping a real platform-eng role at only 41 — exactly the spec's thesis that keyword scoring is the weak baseline and the cited LLM scorer is the differentiator (unit-tested vs a mocked gateway; a live scored run needs the gateway token). Honest known-issues → M2 (not blockers): Swiss coverage = 0 keyless (arbeitnow is a DE board), the JSON-LD adapter defaults to jobs.ch (repoint at employer career pages before use), the live path needs OLL_MODEL_SERVICE_TOKEN. Four decisions wait for you this morning. Gate green.

Fri · Jul 10 · 2026

📐 The agentic job scout — the complete spec

Spec of record

The one build-ready spec — it folds the v0 draft, the techniques teardown, and the seam architecture into a single canonical source, and leads with the driving question: what do we already have vs what else do we need? The answer is the thesis — don't build a job scout, re-aim the distribution scout on the spines you already own: the OpenCLAW loop (heartbeat→watch→score→dedup→draft→digest→persist), the oll-model gateway (cost-capped scoring), oll-memory (hybrid dense+keyword+RRF prefilter), the oll-mcp seam, Core (magic-link + Stripe subscription = the paid gate), and Telegram are all live; the real delta is a thin service adding a versioned profile, JSON-LD source-watchers + one aggregator + manual paste, two-stage cited-rationale matching with honest abstention, cross-source dedup, a tiered digest, and the paid multi-user layer. It names the one architecture decision (recommend the HYBRID — an oll-scout service owns data/state/sources/billing while an agent runtime owns the reasoning and the OpenCLAW loop owns cadence), the ten-stage pipeline (house boxes-and-arrows diagram), the six-table user-keyed data model, legal sourcing (10 CH career pages + one aggregator, never LinkedIn/Indeed), the MCP surface with NO submit tool by construction, the CHF 19/mo Career-Radar gate, the AIOps observability + cost-gradient layer, the earliest-chargeable-slice build sequence (M1→M4, M3 is the chargeable milestone), and the open decisions. Single next action: M1 — profile + first JSON-LD watcher + cited-rationale rubric on the proven loop; no submit tool, ever. Gate green.

🎯 The best agentic job search + alert — the techniques

Reference · techniques

One level below the seam plan: the concrete techniques that make an agentic job scout better than a keyword alert — each traced to code we already run or a source we can cite. The engine is not new to invent: OpenCLAW's live distribution scout is already an 8-stage watch→score→draft→digest loop (heartbeat + keyword pre-filter + LLM relevance-score ≥7 + 30-day dedup + Telegram digest + seen-state), ~90% reusable — only the source-watchers and the draft step change. Postiz (code-verified from gitroomhq/postiz-app) supplies the well-behaved tool-seam: one write tool + many read-only/idempotent discovery tools, discovery-then-act enforced by schema, a type enum with draft as the safe default, errors-as-corrective-data, array-batching to beat the rate limit — with the crucial house twist that OUR scout registers NO submit tool at all (cannot auto-apply by construction). The differentiator is the matching engine: hybrid dense+BM25+RRF retrieve-then-rerank, a structured profile (0.84 vs 0.67 human correlation), cited-rationale rubrics that quote before they score, honest abstention. Plus legal sourcing (JSON-LD career pages + free aggregator tiers, never LinkedIn/Indeed — hiQ lost on contract), digest-not-ping alerting, and an AIOps layer (cost gradient, self-monitoring, human-in-the-loop, never auto-apply). Now consolidated into the spec of record above. Gate green.

Jul 10Open →

🔌 The agentic seam + the oll.in positioning wedge

Reference · strategy

Two reads that set up today's spec of record. The seam architecture establishes the job scout is not a new thing to invent but a proven live pattern — agent runtime + MCP tool-seam + human-approved action (OpenCLAW reasons, oll-mcp is the one seam, Postiz proves the last hop) — mapping discover→read→ground→tailor→verify→act onto thin scout tools over the live spines, with a pre-flight scout_consistency_check and the hard guardrail that no auto-submit tool exists (assistierend statt autonom). The positioning study reads careerset.com's mirror (validated-but-mature, moat = distribution not features) and the honest inventory (POC-rich, ship-poor), landing the wedge: win on the Bewerbungsfoto on-ramp, agentic-not-toolbox, corpus-grounded, Swiss pay-once — the scout is dogfood + AIOps portfolio, not the first franc. Both now feed the complete spec. Gate green.

Wed · Jul 8 · 2026

📚 oll.in — SEO content deepened to 7 guides + a publishing calendar

Product · build

The organic-acquisition layer extended: 4 more evergreen pillars (motivationsschreiben · bewerbung-mit-ki · ats-schweiz · swiss-cv-for-expats), so /guides now covers 7 of the researched angles. Same server-rendered FAQPage/HowTo/BreadcrumbList schema, EN+DE full parity, honest fact-handling (no hard AI-detection percentages stated — reframed as directional; ATS framed as "insurance, not the whole game"). tsc + build clean (38 routes), all 7 guides verified 200 in EN+DE with JSON-LD parse-clean. Plus a seasonal publishing calendar folded into the GTM brief (January + August Swiss hiring peaks; which pillars refresh vs date-only evergreen). Local commit 79f952a on feat/v2-guest-photo; nothing deployed/merged/pushed. Gate green.

🌅 oll.in — night-shift brief: the sell layer, built & verified

Product · milestone

An overnight "make it sell" run turned the built product into a sell-ready one, all documented on main, nothing deployed/merged/posted. Shipped + verified by running: the GTM "How It Sells" brief (ApplyCH reframe · expat beachhead · battlecard · pricing fixes), an expat-first landing (marketing / + funnel at /app, 8 conversion moves, EN+DE), 3 schema'd SEO guide pages, a live-probe-grounded deploy runbook, staged distribution drafts, and an adversarial review that fixed two dishonest landing claims and verdicted the whole surface solid. The headline: a live health probe confirms the CHF 9 dossier money path is one deploy away — Core + oll-write + oll-memory are live; the blocker is the frontend going up + the Stripe webhook, not missing product. The CHF 29 photo waits on PR #92 (foto upload) + #84. Full brief + the tight decision list for Sam. Gate green.

🚀 oll.in — the one-step deploy runbook (take v1 live → first franc)

Product · deploy

The one unlock only Sam can do, made frictionless: the exact ordered sequence from localhost to a stranger's first franc — grounded in the real BFF env, with a live health probe (Jul 8) settling what's actually up. Good news first: every backend the CHF 9 dossier money path needs is already healthy over HTTPS — Core (200), oll-write (200), oll-memory (200), and the oll-model gateway behind write (200, at model.oll.am not oll-model.oll.am). The first franc is not blocked on standing up backends; it's blocked on (a) publishing the Next.js frontend — and oll.in has no git remote today (verified), so step 0 is creating one; and (b) finishing Core's money path — the known blocker being the live Stripe webhook at core.oll.am/api/billing/webhook + STRIPE_WEBHOOK_SECRET (without it a payment succeeds but the plan never flips to pro). Includes the publish decision (Coolify-on-VPS recommended vs Vercel), the exact prod env manifest, a keys-to-rotate table, a Sam-only-vs-automatable split, and a follow-literally smoke test (magic-link → dossier → CHF 9 test then live → download). foto.oll.am + scout.oll.am are not up — foto only gates the CHF 29 photo add-on (PR #84, still open), scout only v2 Radar; neither blocks the dossier. Honest throughout: health 200 ≠ ready-to-charge. Gate green.

📣 oll.in — distribution drafts, staged for Sam to post

Product · distribution

The first-100 plan from the GTM brief turned into ready-to-post, honest, value-first copy — staged only, nothing auto-posted. An englishforum.ch Swiss-CV checklist for newcomers (photo · permit · Motivationsschreiben · Zeugnis · structure · language) that helps first and mentions oll.in once, plainly; two Reddit value-answers (r/Switzerland, r/AmerExit) that are advice-first plus one honest "built this, feedback welcome" show-post; a 5-post LinkedIn build-in-public series (photo flip · the cover letter · the AI-honesty problem · pay-once · the one ask); three reel/TikTok scripts ("Swiss CV vs your CV," myth-busting); and a university-career-center outreach email offering a free checklist/workshop. Beachhead = English-speaking expats ("your CV is fine, it's just not Swiss"); every draft leads with genuine help. Honesty guardrails held: a clear STAGED-ONLY banner (Sam reviews + posts each himself; no mass-DM, no scraping, no automation), no "Swiss-hosted" claim, no detector-evasion framing, no invented stats or testimonials, and nothing implying a state/RAV/university endorsement. Gate green.

📈 oll.in — 3 SEO content pillars built (rank + funnel, schema'd, EN+DE)

Product · build

The organic-acquisition layer: a /guides hub + three evergreen pillar pages that capture Swiss job-search intent and funnel into the product. swiss-cv-format (the tabellarischer Lebenslauf, 8 quotable rules → /app), rav-applications (the monthly requirement + Stellennachweis → /app), bewerbungsfoto (Swiss photo rules + honest AI answer → /photo). Each server-renders FAQPage + HowTo + BreadcrumbList JSON-LD (what AI answer engines lift), with per-page canonical + metadata, EN+DE full parity (DE = primary market). Honesty held with real care: the RAV figure is "8–12, set individually — confirm yours" (no false legal mandate), the AI-photo line warns it must still look like you, no oll.in usage stats invented. tsc + build clean (34 routes), Playwright-verified incl. JSON-LD parses + DE toggle flips content and schema inLanguage. Flag for Sam: real hreflang needs a per-locale URL architecture (/de/ /en/) — omitted (not faked) since the app is cookie-based. Local commit e900e80; nothing deployed/merged/pushed. Gate green.

🛒 oll.in — the expat-first landing that sells is built

Product · build

The GTM brief's #1 make-it-sell task shipped: a dedicated marketing / (funnel cleanly moved to /app), embodying all eight research-backed conversion moves, verified by running. Expat-first hero ("Your CV is fine. It's just not Swiss.") · a working grounded-receipt reveal (click a claim → "← from your CV: …") · the "we will NOT invent" pledge · free-preview-before-pay · a 4-way comparison table (oll.in vs ChatGPT vs Profile Bakery vs auto-apply) · a Swiss-format proof block (photo 3.5×4.5cm top-right, permit B/C/L, DE/FR/IT/EN) · an explicit anti-auto-apply stance · pay-once/guest badges with CHF 9 on screen one. Built on v1 tokens, EN+DE via next-intl (full key parity), tsc + build clean (30 routes), Playwright-verified in both languages. Honesty held: no "Swiss-hosted" claim, no fake testimonials/counts, market stats framed as context. Two Sam confirms: the grounded-receipt is a labelled example (live one = the funnel), and the money-back badge is an honorable manual-refund promise. Local commit e0259b6 on feat/v2-guest-photo; nothing deployed/merged/pushed. Gate green.

🎯 oll.in — "How It Sells": GTM synthesized from 3 research streams

Product · GTM

Night-shift research (competitors · customers+distribution · Swiss SEO, all verified July 2026) synthesized into one go-to-market brief. The reframe: oll.in is not the first Swiss AI-application tool — ApplyCH (DE/FR/IT/EN, RAV Stellennachweis auto-fill, CHF 9.99/mo) and Profile Bakery (photo + blank CV template, pay-once) already occupy the space. But the market has turned hard against fabrication (94% of employers see fabricated AI info; recruiters spot AI resumes in ~20s) and nobody claims "grounded, cited, never invented" — that whitespace, plus pay-once and the headshot bundle, is the wedge ApplyCH can't match. Beachhead = English-speaking expats ("your CV is fine, it's just not Swiss"); RAV cohort second (multi-packs, honest Stellennachweis-fill); grads the word-of-mouth flywheel. Pricing validated with two fixes: add dossier multi-packs (5/10), fix-or-defer the CHF 19/mo Radar (too high vs ApplyCH), keep CHF 29 photo. Plus the SEO plan (win commercial terms + the bundle + RAV; .in gives no CH geo-signal; allow AI-search bots), eight copy-ready landing moves (live grounded-receipt · free preview before pay · 4-way comparison), and a prioritized make-it-sell task list now driving the night. Gate green.

🏗️ oll.in v2 — all five items BUILT + TESTED (5-agent workflow → adversarial review-fix)

Product · build

The full v2 was implemented and tested in one orchestrated pass — a 5-agent workflow (parallel backend → serialized frontend → an adversarial review-fix that ran everything), ~920k tokens. Landed, each verified by running (not read): v2.1 foto selfie-upload/storage endpoint → PR #92 (65 tests green, magic-byte sniffing + path-traversal-safe, real upload→checkout curl); v2.2 Career Radar — oll-scout promoted to a real service → PR #93 (50 tests, per-user tick + Core-email digest + ownership isolation), /radar renders real scored matches with a live filter + dossier hand-off; v2.3 Get-found/get-found drafts real corpus-grounded posts, Postiz/LinkedIn honestly gated (real 501, never fake-scheduled); v2.4 Ollie — review-queue proven end-to-end (real match → real cited dossier → draft, nothing sent, human-on-send only); v2.5 Tracker+/DE — status pipeline + recipient-scoped RAV reminder + German via next-intl. The review-fix earned its keep: it caught + fixed a real broken hop (Radar BFF hit the now-auth-required scout with no Bearer → 0 matches → Ollie prepared nothing) and de-staled a self-contradictory foto comment. Honest not-solid caveats carried forward: full paid /photo path needs Core guest-checkout running (mocked-test-covered); real headshots need a pinned Replicate model; the Radar anon preview + the DE walk are now closed + verified — a public no-auth sample-matches endpoint (PR #93) makes logged-out /radar show real scored cards with zero 401s in prod, and a German Playwright walk found + fixed a real next-intl wiring gap (/photo + /radar were English under a German shell). Backend = PRs (your merge-gate); frontend = local on feat/v2-guest-photo (oll.in has no remote). Nothing deployed or merged. Gate green.

📸 oll.in v2.1 — the Guest Photo funnel is built (frontend, verified running)

Product · build

v2 implementation started at the plan's #1 — the no-login /photo Bewerbungsfoto funnel — built and verified by running on branch feat/v2-guest-photo in the oll.in app. A 3-step flow (upload 4–8 snaps → Swiss style pick → CHF 29 pay-once, price on screen one) + a Stripe-return page driven by foto's real FulfillResponse state machine, with BFF routes mirroring services/foto/openapi.yaml exactly and built entirely on v1's design tokens — same product, no reinvented UI. Verified honestly: tsc + build clean (25 routes), foto-service booted locally, a Playwright walk drove upload→pay through the real browser→BFF→foto hop; the only blocked link (foto→Core→Stripe) surfaces foto's genuine CORE_UNAVAILABLE error rather than a fake success, because Core's guest endpoints (PR #84) aren't merged yet. Two green PRs (#84 Core guest-checkout, #85 foto front door) await Sam's merge; one real backend gap remains — foto has no selfie-upload/storage endpoint yet (flagged in the UI, not faked). Nothing deployed or merged. Gate green.

🩺 oll.in v2 — three critiques folded in (pricing coherence · data-gated sequencing · Ollie's real cost)

Product · refinement

Sam pressure-tested the v2 plan + no-brainer brief; all three critiques were right and are now in the docs. (1) Pricing ladder coherence — CHF 9/application silently out-costs the CHF 99 Pass for a RAV seeker (10–12 apps/mo = CHF 90–108) and makes Radar look strangely cheap; fixed by framing CHF 9 as a capped trial rung ("the Pass pays for itself by application #11") so the page does the arithmetic for the buyer. (2) Sequencing v2.2 vs v2.3 — Radar-before-Get-found is architecturally right but strategically a data call, not a now call: Get-found needs only LinkedIn OAuth + a prompt and is what employed-and-curious users want first; the gate order is now a data-gated fork the waitlist + first francs vote on (the attribution nights). (3) Ollie's hidden cost — a per-user OpenCLAW runtime is a capacity model, not a route + delta; flagged as the one v2 item that may need new infrastructure, effort relabelled "L + infra", and the overreaching "v2 needs no new infra" line corrected. Gate green.

🎯 oll.in — the no-brainer sell (3 research streams synthesized)

Product · positioning

Three research streams — competitors + positioning, conversion UI/UX, and the user journey — synthesized with verified July-2026 pricing into one decision-oriented brief. The finding that reframes the strategy: the "all-in-one Swiss bundle" is not greenfield — Profile Bakery (Zürich) already bundles headshot + CV + cover letter at €29.90 pay-once. So "we bundle" is table stakes; the defensible wedge is grounding + honest abstention + genuinely Swiss-correct output, which nobody in the 13-competitor field does. The play: lead with the felt outcome (a finished, sendable Swiss dossier — the 3 things a chatbot structurally can't do: emit a Swiss PDF, make a headshot, ground/abstain vs your CV), prove with the moat on screen (a citation resolving + one honest gap), reinforce with pay-once. Plus the critical pricing-unit fix (CHF 9 = one complete application, headshot as +CHF 20 add-on never standalone), the 6-moment conversion journey (value→trust→ownership→pay, all before login; guest checkout + TWINT + money-back), and the honest risk (grounding is the hardest thing to make a cold buyer feel). Ends with five batched calls for Sam. Gate green.

🧭 oll.in v2 plan — concrete, on top of the MVP

Product · roadmap

With v1 now real (the Next.js dossier app on the frozen spines), v2 stops being a wishlist and becomes small additions that reuse the MVP. The leverage thesis made concrete: Career Radar is "point the existing dossier route at a scheduled job feed" (oll-scout built, reuses preferences + applications CRUD); Ollie is "drive the exact v1 verbs autonomously over the proven MCP seam, review inbox = /applications"; Get-found is a draft-post variant of generation + Postiz; the guest headshot is foto + Core guest-checkout. Each item gets its concrete frontend route + backend delta + the ONE input it needs + effort (S/M/L), sequenced revenue-ready-first: v2.1 guest photo (CHF 29) → v2.2 Career Radar (CHF 19/mo) → v2.3 Get-found → v2.4 Ollie the agent → v2.5 tracker+/DE. The money model holds the honest line — own the tool (pay once), subscribe to the work. Gate: v1 deploys + earns first franc, then v2 one capability at a time. Gate green.

🗂 oll.in feature scope — v1 MVP · v2 deferred · out of scope

Product · scope

The product got simplified and the scope written down. After a design study (four directions → a clean combined synthesis) and the pivot to a Next.js rebuild, the scope is locked: v1 = one loop — paste a job → a grounded, cited application from your CV (tailored Swiss CV · cover letter · interview prep · live headshot) → take it — all real, proven on the frozen spines, no new backend needed. v2 = deferred (Career Radar, Get-found, the Ollie/MCP agent, guest headshot checkout) — mostly already built but each needs an input (Jooble key, LinkedIn OAuth) or scale, so they wait for post-revenue. Out of scope forever = the honesty lines: no auto-apply/mass-apply (the human always sends), no scraping/auto-connect (official OAuth only), no fabrication (grounded + honest abstain), no "Swiss-hosted" claim. The rationale: ship the one real, valuable loop; the frozen spines make every v2 feature a small addition, not a rebuild. The clean Next.js build of v1 is in progress. Gate green.

🔗 oll.in grounded dossier — end-to-end on the REAL services

POC · closed loop

The oll.in grounding loop is now closed on real code — no stand-ins. PR #91 chains the real oll-memory retrieval into the real oll-write dossier verbs, keyless: boot oll-memory (local pgvector) → ingest the synthetic corpus → assemble a numbered cited profile_context → call tailor_cv + cover_letter with it. The proof is the citation-trace: every [n] the verbs cite resolves back to a real RRF-scored retrieved passage (5 tests assert citations ⊆ retrieved evidence), and a genuine gap — French/Romandie, absent from the candidate's corpus — abstains and gap-marks ([gap: professional French … omitted rather than fabricated]) instead of inventing it. 5 tests pass on a live stack. Only the text generation is still the offline mock (pipeline proof, not prose — that's the separate quality preview). Prod/Neon untouched; nothing merged/deployed. Gate green.

🧠 Memory spine merged to main — PR #80 (oll-memory)

Platform · merge

Sam gave the go and I merged PR #80services/oll-memory/, the document-intelligence spine (LlamaIndex; consolidates the old ingest+rag+extract split into ONE service) — into main. All 26 CI checks green (oll-memory lint+test on pgvector, docker boot+health, pip-audit; plus foto/model/write unaffected), MERGEABLE/CLEAN, squash-merged (08cce3a). Per the branch model a merge to main does not deploy — this lands the code as the single source of truth (memory.oll.am was already deployed separately). This is the real service the oll.in RAG POC stood in for locally, so it directly unlocked the next step — now done: PR #90 upgrades the oll.in grounding POC from its stand-in to run against this real oll-memory. Booted keyless (its own Docker image, deterministic local embedder, a local pgvector container — never prod/Neon): health green, 6 synthetic docs → 7 chunks into real pgvector, all 6 job facets retrieved real cited passages, per-user ACL isolation holds, and an off-corpus query honestly abstained (top RRF score at the single-retriever ceiling, below the dual-retriever floor — no fabricated citation). 4 tests pass against the live service. One step remains for a full grounded dossier: feed the cited context blob into the tailor_cv/cover_letter verbs (a keyless oll-write call) — held out to keep this POC scoped to retrieval.

📄 oll.in dossier quality preview — is it good enough to send?

POC · quality

The demo proves the pipeline but runs a mock model — so it can't answer the only question that matters: is the dossier send-worthy? This page answers it. A full tailored dossier generated with oll.in's actual tailor_cv / cover_letter / interview_prep system prompts on the synthetic Lena Brunner → Helvetia Senior Data Analyst case, at real-model quality: a Swiss-format CV, a cover letter, and six interview questions with why/angle. The case is a fair test because it has both real matches to foreground (dbt/BigQuery, Tableau, A/B testing, and genuine insurance-domain experience at Die Mobiliar) and one genuine gap — the JD wants mentoring two junior analysts, which Lena's profile doesn't support. Watch how all three artifacts handle it: the CV emits a [gap] marker, the letter names it as a growth step instead of faking leadership, and the interview prep coaches an honest bridge. This is POC-A's send-worthiness gate, made judgeable — if it reads as send-worthy, going live is a single env flip to a real model; if not, the fix is prompt-only. Nothing deployed. Gate green.

Tue · Jul 7 · 2026

🧭 oll.in — from solution architecture to three executed POCs

Architecture → POC

Drew the whole oll.in product as a system, then verified it into working code. The solution architecture found ~80% already exists as frozen spines — the genuinely-new backend is just 3 oll-write verbs, one oll-scout service, a Core event-id dedupe table, and a Postiz deploy — and chunked the rest into six parallel POC lanes. The plan→execution spec grounded that against the running services (two corrections: oll-write is stateless → grounding is a BFF job; Core already does subscriptions → Radar billing is reuse) and settled POC-C — scout source = Jooble (+ Arbeitnow; govt/LinkedIn/Indeed all RED, concentration risk flagged). Then three POCs executed on synthetic data, verified by running: PR #87 dossier verbs (172 tests, gap-marker fires), PR #88 oll-scout (32 tests, Docker-healthy digest), PR #86 synthetic RAG (retrieval + honest abstain). Nothing merged/deployed. Gate green.

🖥 oll.in — POC showcase demo + local dev-test manual

POC · demo + runbook

Made the POCs something you can click and run, not just read. The showcase (PR #89) is a one-command keyless Flask "demo BFF" that loads oll-write + oll-scout in-process, seeds the synthetic RAG, and serves three live panels — evidence (cited retrieval + honest abstain), dossier (tailored CV/cover/interview with [n] citations + gap-markers), and Career Radar (live scored digest) — verified running + Playwright-screenshotted. The dev-test manual is a step-by-step local runbook (sh scripts/poc_demo.sh:8099), every command run from a clean checkout before writing (54 tests green; caught a real scout --once CWD gotcha). Retrieval/scoring/citations are real; generation is a mock stub. Nothing deployed. Gate green.

✂️ oll.in MVP — the feature cut, an interactive Ship/Trim/Defer board

Product · scope

Every oll.in feature enumerated and asked one question: is it needed to take a stranger's franc? An interactive board (tap a row to cycle Ship → Trim → Defer, persists locally) over all 30 features grouped by area, defaulting to the recommendation: lead with the CHF 29 headshot (foto-service — already scaffolded on Core, no login) plus a "prepare my application" writing tool (paste a role → tailored CV + cover letter + honest gap-check on oll-model, no scraping / auto-send / ToS risk), and defer the whole automation vision (Ollie finds jobs, Career Radar, Get-found posting, auto-apply, integrations) to post-revenue — each is a new engine. Grounds the cut in a buildability lens (real-now on Core / Model / foto vs new-engine), spells out the design adjustments each cut implies, a go-live sequence, and six yes/no decisions. Ship-vs-build stated up front: the prototype is a mockup; the fastest franc is the photo. Sits with the style system and the landing build spec. Gate green.

🎨 oll.in Style System — one product, three switchable skins

Product · design system

The whole oll.in clickable prototype became live-switchable between Bold · Clean · Warm (× light/dark) from ONE token system — same content and markup, only the skin changes, persisted across screen-to-screen nav. Every product screen (dashboard incl. the explainer + "Ollie's on it" reel, applications, get-found, radar, settings, role, apply, onboarding) was refactored off hard-coded Bold values onto CSS custom properties keyed by data-style × data-theme on the root — colour, geometry (border width / colour, radius), type and shadow all tokenised, with minimal per-style overrides where the aesthetics genuinely differ (weight, casing, Warm's serif display). The doc explains the token architecture and recommends Clean as the product skin (calmest across dense screens; Bold stays for the loud landing), decidable on real screens then collapsed to one skin by deleting the losing token blocks. Verified across all six combinations, 0 console errors, cross-screen persistence. Sits with the MVP cut and the landing design study. Gate green.

📐 oll.in Landing — Build Spec 2.0, one source of truth for every landing pass

Product · build spec

Every directive the owner has given for the flagship landing, deduplicated into ONE authoritative brief — so future passes reference this instead of re-prompting from scattered chat. It organises eleven requirement groups, each stated as checkable rules: the audience (everyday seekers — nurses, teachers, tradespeople, admin, care, sales, hospitality; the ChatGPT-DIY / LinkedIn-Premium status quo; three sub-audiences — searching / passive / growth-minded; DACH-wide, not Switzerland-limited; the "100+ applications, only silence" emotional core); what we sell (the OUTCOME — get the interview / get found / get an answer — never lead with mechanism; the Measure·Prove·Act·Distribute machine is INTERNAL vision only); Ollie/Olli (the agent is a named person, "prepares; you review and send", never auto-applies); the two outcomes (get seen by applying / get found via OAuth-only presence + always-on Career Radar); the chosen Bold design direction; the maxed-out visual language (generated HTML/CSS, a short hero with a 4-beat animated storyboard of Ollie working, borrow the platform-diagram craft for a non-technical reader, no redundant prose labels); copy discipline (~50% leaner, DRY, zero em-dashes, native German, de-AI'd); honest full pricing (CHF 29 / 49 / 19, NO strike-through, no fake discount — retiring the old struck-price landing); the non-negotiable honesty guardrails (no fake testimonials, prepares-not-sends, no Swiss-hosted claim, launch-target prices); and the behaviour/tech contract (single file, EN/DE, dark mode, reveal-on-scroll with 1400ms crawler-safe fallback, full OG/JSON-LD SEO). One open decision flagged: CHF vs € for the DACH market. Cross-links the design study, landing case study and launch kit. Naming-safe (Core + Model), no hosting claims. Gate green.

🌱 Platform 3.0 — the always-warm job corpus + your data as a product

Vision · future work

Extended: the vision doc still leads with the always-warm job corpus, and now adds a new "Your data, as a product" section — the Measure + Prove pillars turned into a user-facing surface, sitting ALONGSIDE Ollie on the same data. The corpus hero is unchanged: a cron scout (OpenCLAW) pulls fresh postings from legal job APIs (Adzuna · Arbeitnow · Jooble) → embedded (Model · nomic-embed-text) → stored in the Memory spine (pgvector) as a live, always-warm JOB corpus, matched against the user's own experience corpus so a visitor lands to real, matched jobs. The new section makes the same data — job corpus + your application funnel + interaction signals, all in Memory — a product surface you touch directly, rendered as a house boxes diagram with three faces over one data layer: Chat with your data (DataFast's AI-analyst pattern — NL→query/retrieve→answer over your own job-search data: "which applications got a reply?", "what's my interview rate?"); Insights, like DataFast (response/ghost rate, interview-conversion %, time-to-reply, which CV/channel/role converts — the Measure pillar shown, not jargon); and a Verified track record (un-fakeable because it rides on Ollie's own logged actions — applications actually sent, replies actually received — the Prove pillar made a credential, TrustMRR-vibes for a career). Grounded in the job vertical first ("chat with your job search" + "your live personal job-market DB"); the general horizontal — a self-hosted, agentic, chattable, verifiable DB-as-a-service for any data — is explicitly kept as the tail, not the head. It's reuse, not a new build: Memory IS the DB/RAG, oll-model does NL→query + chat + insight generation, the data is already captured — additive UI + a thin query/insight layer, zero new backend services (the reuse ledger is extended to say so). Honesty kept; still deferred behind the CHF 29 first franc, but "chat with your data / see your insights" is flagged as another conversion hook alongside instant-jobs-on-landing. Cross-links Platform 2.0, the Memory spine, the agent seam and the Constellation. Naming-safe (Core + Model), no hosting claims. Gate green.

🎨 oll.in landing design study — three content-frozen style directions

Product · design study

A UX/UI design study on the oll.in flagship landing: three distinct visual directions — Clean · Warm · Bold — explored so the look can be chosen without touching the honest copy. The method is the point: each direction is a content-frozen restyle — the body, copy, prices, EN/DE i18n and behaviour are byte-identical, only the <style> block and fonts change — so any direction is a drop-in swap and the honesty architecture (the positioning moat) is never disturbed. The case study describes each with its type system, real palette swatches, section treatment, dark-mode character and who-it's-for: Clean (Inter grotesk, cool neutrals, hairline borders — quietly premium, Linear/Vercel), Warm (Fraunces + Nunito Sans, cream + terracotta/sage/ochre, candlelit dark — human, on the anxious seeker's side), Bold (oversized uppercase Fraunces, Swiss-red colour-blocking, hard offset shadows — stops the scroll). The three live as local previews (landing/ollin-pro-{clean,warm,bold}.html at :8140), not deployed pages; recommendation pending — Sam picks, then the chosen style applies to the full-content ollin-pro.html. Sits with the landing case study and the launch kit. Gate green.

🧬 Merge-to-main clean-deploy runbook — converging the branch sprawl, Memory first

Release eng · runbook

The ordered plan to fold 14 open feat/* branches into main without tangling — surveyed read-only (nothing merged/rebased/pushed; merging is Sam's per-PR call). The survey found the sprawl is far less knotted than the branch count implies: zero branches conflict in source code — the only merge-tree conflicts are in state/state.json + site/build-log.html (generated state + hand-written rail, which vanish on rebase). And 4 of 10 open PRs are retire-on-sight duplicates: PR #80 feat/oll-memory consolidates ingest+RAG+extract into ONE LlamaIndex service, superseding #75/#76/#77; the thin proven oll-mcp seam supersedes the heavy #79. The runbook carries a full inventory table (branch · what · code|docs · touches-frozen? · diverged-by · clean? · verdict), the dependency-ordered sequence — Memory merges FIRST (its code is deployed at memory.oll.am but lives off-trunk, so landing it makes main the source of truth and gives the stacked #81 verse-reingest something to rebase onto), then the low-risk independents, then the Core/Model money-path fixes last (each needs adversarial verify + Sam-go) — the concrete per-branch git rebase origin/main recipe + conflict triage, and the decoupled clean-deploy section (tag a green commit or dispatch deploy-all.yml; T0 Core·Model·Memory → T1 foto·write → T2 site, health-gated; Memory's "deploy" is a re-point of the live service to the main-built image). Naming-safe (Core + Model), no hosting claims. Gate green.

🇨🇭 oll.in — how the market actually talks (grounded personas + voice bank)

Market voice · research

A grounded listen into how everyday Swiss/DACH job seekers really describe the hunt — so oll.in's copy and distribution mirror their language, not marketing's. It maps the ten recurring pains in the community's own words (the rejection-count scoreboard, self-blame, ghosting-as-norm, Motivationsschreiben dread, weak-German anxiety, the Arbeitszeugnis "secret code", the Anerkennung chicken-and-egg, Vitamin B, the no-experience catch-22), a DE/EN voice-and-vocabulary bank with an explicit avoid list (no "AI-powered", no "10x", no "sell yourself", no "auto-apply"), six illustrative synthetic personas (Marina/Dejan/Reto/Priya/Sabrina/Thomas — composites, never real people), and five honest copy proposals for the landing (lead with being SEEN, normalize-then-help, "you review and send" as a headline, Swiss unknowns as trust hooks, voice-by-trade). Honest method caveat throughout: Reddit + englishforum block automated fetch, so it's directionally reliable — verbatim pulls to confirm in-browser. Sits with the launch kit and the landing case study. Gate green.

🧭 The single living plan is restored — oll.in, in order

Plan of record · roadmap

The plan-of-record page CLAUDE.md points at is back — oll-am-plan.html, the ONE to-do until a stranger completes the value ladder. It frames oll.in as THE flagship (the agentic Swiss job-application agent for everyday job seekers — nurse, teacher, tradesperson, admin — not devs) whose whole platform is already live; what's missing is the sellable front door. Three steps, strictly in order, mapped to the CHF 29 → CHF 99 → CHF 19/mo value ladder: Step 1 un-park foto (the first franc — backend is code-verified done, blocked only at the sell/infra gate) as a two-lane checklist (Claude's code: re-land the Core guest-checkout pair, foto Coolify config, the one net-new buyer checkout page · Sam's console: Stripe one-time prices + live webhook + Replicate token + shot.oll.am); Step 2 build the agent's job-scout half (Adzuna/Arbeitnow/Jooble — the drafting half already ships) to power the CHF 99 pass; Step 3 the distribution playbook → CHF 19/mo Career Radar for first recurring MRR. Ends on the honest ship-not-build note: this whole roadmap is the last mile of already-live infrastructure — the only net-new code is the Step-1 checkout page + the Step-2 job APIs. Links (not duplicates) to the Overnight Plan for the migration-brief detail. Gate green.

🇨🇭 oll.in — the landing & product design, decoded

Product · landing design

A case study of the oll.in conversion landing — the Swiss/DACH job-application agent for everyday job seekers (nurses, teachers, tradespeople, care, admin, hospitality), not software engineers — teaching the WHY behind the page. It walks the nine-section conversion architecture (agent-at-work hero dashboard → the enemy comparison → Scout/Match/Prepare/Track → Career-SEO "get found" → the professions grid → the illustrative Sofia/Marco/Luka walkthroughs → founding pricing → the founder → the waitlist close), the three signature moments (the live activity feed, the before/after Bewerbungsfoto using the founder's own generated photo, the real profession photos), the full EN/DE toggle, and the founding-price lifecycle (50% struck prices, waitlist doesn't charge). The through-line is the honesty architecture as the positioning moat — no fabricated testimonials, the agent prepares while the human sends, launch-target prices, no "Swiss-hosted" claim, full stock-vs-founder photo disclosure. Sits with the launch kit and the Agent Seam plan. (The landing itself is the working-tree landing/ollin-pro.html, a preview, not yet a deployed page.)

🇨🇭 oll.in launch & distribution kit — night-shift research, ready to act

Launch · distribution

Night-shift research turned into an actionable, honesty-safe kit for oll.in. It sets out the competitive landscape and the six-point positioning moat, the first-dollar plan (sell the CHF 15/29 Bewerbungsfoto now, keep the CHF 24/49 Job Hunt + CHF 9/19 Radar as waitlist reservations), six copy-paste-ready distribution posts, a 20-keyword SEO plan, and the one action this week. Sits with the landing case study and the market-voice research. Gate green.

Mon · Jul 6 · 2026

🏛️ Platform 2.0 is now canonical in The Platform — and the agent layer is LIVE, not planned

Architecture · truth-up

Sam's ready-made Platform 2.0 vision is folded into the canonical architecture page, with one load-bearing correction: the agent layer flipped from "planned" (purple) to LIVE (green). The full constellation now lives inside The Platform — after the extension layer, before the ADRs — in house style: the three spines (Core core.oll.am · Model model.oll.am · Memory memory.oll.am, all returned 200 today), the oll.in career-agent flow "E" (one "Apply" swipe → all three spines + Replicate + distribution), the 2.0 relationship table, the invariants, and the views roadmap. The truth-up: OpenCLAW is live on the VPS (:18789, 5+ weeks) and — proven tonight in Sam's actual OpenCLAW chat — drives oll.am end-to-end: OpenCLAW → the thin oll-mcp FastMCP seam → live write.oll.am returning real Groq output (llama-3.1-8b-instant), over both stdio and HTTP, authed with a real Core JWT. Tools live today: ollam_clarify · ollam_rewrite · ollam_draft · ollam_spec · ollam_account; the richer oll.in v2 tools (headshot/CV/cover-letter/interview/memory) stay labelled planned. Net effect: oll.in (the flagship) is now technically unblocked — the gate is the first stranger franc, no longer capability. Cross-links (not duplicates): the deployed constellation, the ecosystem narrative, the agent-seam plan. Now drawn, not just described: the section gained four real inline-SVG diagrams in the page's exact C4 vocabulary — a full Platform 2.0 constellation container (three green spines · blue products · the live green agent client · grey planned distribution · dashed externals, with legend), the live agent-seam C4-dynamic call sequence (the proven OpenCLAW → oll-mcp → Core/Model/Memory loop, real output over stdio + HTTP), the oll.in career-agent sequence (one "Apply" swipe composes all three spines + Replicate), and a retrieval-first mini ("retrieval is the product, generation is garnish"). Gate green (tokens · links · nav · naming).

📊 TrustMRR last-month delta — the board is up 31%, the median company is flat

Market intelligence · live data

A live read of the top-1,000 indie-SaaS startups on TrustMRR (pulled today) and how their MRR actually moved in 30 days — honest, dollar-weighted, no invented numbers. The cohort (n=800 with real MRR + a growth reading) added +$3.04M/mo (+31%) to $12.87M — but that headline is a trap the piece refuses to cheerlead: breadth is flat (39% growing / 38% shrinking / 23% flat; median growth ≈0%), and the top-10 gainers are 52% of ALL MRR added. It's a power-law index dragged up by a few compounders over a hollow middle — "the market is up 31%" and "the median founder had a flat month" are both true, and holding both is the lesson. Teaches the why (dollar-weighted ≠ median; percentage growth is noise below a ~$1k base — the +5,659% mean is a data artifact off an "Anonymous startup" at +1,298,336%). Names the movers: Stan +$1.07M (one company = a third of the net add), breakouts Kibu (+$230k) and OSS Postiz (+$155k, on our own deploy shortlist); the biggest loser Brand On Demand −$544k. The AI paradox — 113 startups, 70% growing, but ~$7k avg MRR each: velocity ≠ revenue. US = $1.75M of the +$3.04M; Switzerland +$3.3k across 5 names — the pay-once/privacy lane oll.am was built for is still empty. Ends on the guardrail: this is intelligence, not a work order — the single next action is still the first stranger dollar (LIVE Stripe webhook on core.oll.am), not more analysis. Sits with Strategy + the Control Room.

🌌 The Constellation — Platform 2.0, expanded, is mostly ALREADY deployed

VPS audit · reuse-first plan

Grounded in a read-only VPS audit tonight (docker ps + inspect, nothing changed): the maxed-out oll.am empire is mostly already running — 25 containers — so maxing it out is reuse + simple wiring, not new code. A real tiered map of what the Hetzner VPS runs right now: infra (Coolify 4.0.0-beta.474 · Traefik v3.6 · Redis 7 · Postgres 15 · sentinel · realtime — all healthy ~2mo) · the three spines (Core core.oll.am · Model model.oll.am · Memory memory.oll.am, all live) · five products (oll-write · CiteBible · the oll.am landing · specview web+api+landing · trendfy app+server+ai-models+landing — trendfy already ships its own image backend; foto/ollshot scaffolded, career agent planned) · and the headline — an agent tier that's already live: the OpenCLAW gateway (host :18789, no Traefik, healthy 5w), the agent + automation runtime Sam already has. The direct answer to "how many more integrations?": none of Postiz/n8n/Listmonk/Plausible/Uptime-Kuma is deployed (verified), so the whole maxed-out delta is ~4 zero-code self-hosted Coolify deploys + exactly ONE thin new-code piece (the MCP seam wiring OpenCLAW ↔ the products). Includes a reuse inventory (already-there → reuse instead of build), a wiring diagram where every "constellation line" is a Coolify env var / webhook / n8n node (config, not code), and a franc-gated reuse-first sequence: NOW = CiteBible's first franc (distribution, Sam-gated) → deploy Postiz → ship the MCP seam → deploy n8n+Listmonk+Plausible → ops housekeeping (restarting springular-server; the diverged 164/36 checkout; verify OpenCLAW's public :18789 is authenticated). The concrete/deployed companion to Platform 2.0; sits with The Agent Seam + The Platform. Research/plan only — no code shipped, franc-first.

🏛️ Platform 2.0 — the Memory spine is LIVE; oll.am now knows the user

Platform milestone · refined vision

oll.am crossed a threshold: the Memory spine went live, so the platform now ships products that know you — cited, personal, agent-drivable — not commodity generation. Platform 1.0 was stateless tools on two frozen spines (Core = identity/billing/email; oll-model = any model, one seam). Platform 2.0 adds the third — Memory (oll-memory, verified live at memory.oll.am) — moving the unit of value from “a text op” (commodity, every tool has it) to “a product that knows you” (cited, sticky, worth paying for again). All three spines are deployed & healthy (health checks 200), and two products already run on the Memory spine, same engine / different corpus, zero code duplication: CiteBible (citebible.oll.am/carry — scripture for the sentence you're carrying → cited passages → write-from; public corpus) and ollwrite (the 3-pane Your Knowledge · Manuscript · Chat memory sidecar; private corpus). Distills the reusable 2.0 product pattern — a corpus + the CARRY UX (intent → retrieve with a relevance floor → cite honestly / abstain on a miss → write-from) + Core auth/billing + an optional MCP agent seam — with the 3-spine diagram and the carry-loop flow rendered as real HTML. Maps what it unlocks (the flagship memory-grounded, cited career agent; carry-pattern verticals; the credits ledger) and lands on the honest ship-vs-build conclusion: the platform is BUILT — the next move is CiteBible's first stranger franc (one Core env flip + rotate 2 secrets + distribute), not more platform. Refines The Third Spine (now shipped, no longer an unpromoted branch) and The Agent Seam (now approved); sits with Beyond the Wrapper + The Platform. Ends with four decisions for Sam. Now extended with a “platform → ecosystem” section that reconciles a Postiz-inspired tool→platform→ecosystem playbook against oll.am's real build-state — a 7-pattern mapping table (open-source funnel · API/MCP · agent module · marketplace · webhooks · Postiz/n8n · platform>product) with franc-proximity, effort, and verdict — and sequences it behind the first franc: users now, then the ~80%-built MCP seam, then open-sourcing ollwrite + deploying Postiz for distribution; marketplace/automation deferred to scale.

🧠 The Third Spine — Memory as oll.am's most valuable platform primitive

Platform extension · research + reflection

Went back over the initial extension research to ask a sharper question — what's the highest-value, most elegant next platform primitive? The answer is already ~90% built. oll.am's elegance is “frozen spines, disposable products,” and today two spines are live and frozen: Identity (Core — auth/billing/email; “who you are, what you paid”) and Model (oll-model — provider-agnostic LLM gateway; “any model, one seam”). The missing third spine is Memory (oll-memory) — a per-user private corpus with retrieval + citation; “what YOU know.” The reveal: it isn't a research bet. It's on an unmerged branch (daf6d7a, LlamaIndex + pgvector + nomic embeddings, hybrid RRF retrieval, generation via the Model spine) and already driven in production form by ollwrite's BFF with seven capabilities (ingest · search · chat · draft · verify-claims · suggest · voice-profile). Its trust boundary is elegant — the browser never names a corpus; the server derives mem:user:{userId} from the Core JWT, so a user cannot reach another's corpus. Honesty is built in (a 0.5 relevance floor + abstained:true on a miss — no fabricated citation), and multi-tenant is already proven (the public “bible” workspace is CiteBible — same engine, a flag not a fork). Why it's the most valuable-for-customers extension: grounded-and-cited output is the product; generic generation is the free sample everyone already gives away. It's sticky (a personal corpus is a switching cost), it composes with everything (grounded ollwrite, cited career apps, any knowledge-vertical), and it fits pay-once. Includes the 3-spine diagram, a ranked extension-options map (★ promote Memory · ★ merge oll-extract · credits ledger · MCP gateway · async jobs · on-device Vault — with each row's real repo build-state), a “knows-you-AND-acts” convergence box tying it to The Agent Seam, and an honest ship-vs-build read (it's not infrastructure-before-income — it's the differentiator that makes the income likelier, and it's mostly built). Extends Beyond the Wrapper + The Platform. Research & reflection only — no code; ends with four decisions for Sam.

🔌 The Agent Seam — extending oll.am for the job-application layer via MCP

Research + build spec · plan only

How does Sam's external agent runtime (“OpenCLAW”) drive oll.am's capabilities for the job-application / career layer (oll.in)? Answer: not a new backend — one MCP seam. The thesis: keep oll.am the frozen capability layer and let the agent be a thin, disposable client that reaches it over MCP — build the surface once and any runtime can drive it (OpenCLAW today, Claude Desktop tomorrow; one build, two payoffs). The doc makes the honest split: content generation (tailored CV, cover letter, headshot, interview prep) is already built and low-risk — oll-write's clarify/draft/rewrite verbs, foto's guest-checkout headshots, the Core auth/billing spine; application execution (find → match → fill forms → submit across LinkedIn/Indeed/ATS) is un-built and hostile — anti-bot, captchas, ToS bans that burn the user's own account. “Apply to 100 jobs an hour” lives entirely in the hard half, and 100 tailored apps is a contradiction — 10 sharp beat 100 generic. Centerpiece is the MCP server build spec (thin stdio server, tools namespaced ollam_*, handler-never-throws, a six-tool surface over existing HTTP endpoints) + the real design decision — the auth model (the server holds a Core JWT for the user; ollam auth magic-link login, atomic 0600 token file; Core stays untouched). The only genuinely-new backend code is two JD-aware oll-write verbs (tailor_cv, cover_letter) — a prompt, not an architecture. Sequenced to respect ship-vs-build: build the seam → Sam dogfoods it locally (incl. the AlpineAI application, the build-in-public story) → sell the assisted pack (paste a JD, get a tailored CV + letter + headshot to submit by hand, CHF 99) → defer the autonomous mass-apply agent until a stranger pays. Plan & reflection only — no code written; ends with three decision points for Sam. Sits with the Beyond the Wrapper research and the platform architecture. Extended (Jul 6): a “Detailed build plan (v1) — thin server, local-test-first” section now makes this the executable spec for the one new-code piece — the oll-mcp stdio server (Python + FastMCP, services/oll-mcp/, ~250 lines). A thin adapter with zero new backend logic over endpoints already live & verified 200 (write.oll.am · memory.oll.am · core.oll.am): file tree, an 8-tool ollam_* surface (write + memory + account), the auth crux (one Core JWT; dev-only mint-jwt using AUTH_JWT_SECRET in core/.env), an 8-step local test plan (mint JWT → mcp dev Inspector → Claude Desktop / Cursor → then verify OpenCLAW's MCP-vs-OpenAI-tools model), and a verified-vs-open table. It's a local/desktop tool — not deployed — sequenced behind the CiteBible franc.

🪶 ollwrite & CiteBible — what's built, what's live (one state read)

Product state · verified

One page that settles the confusing part: CiteBible and ollwrite are the same engine, and the less-built one is the one that's live. CiteBible is the shipped vertical slice of ollwrite — the memory-sidecar's "chat with your corpus" pointed at one public corpus (the World English Bible) and narrowed to one honest job. It's live and working for a stranger right now at citebible.oll.am/carry: type a real human situation, get grounded, verse-level, cited scripture — free, no login, ~6s, with honest abstention (a 0.5 relevance floor; shows nothing rather than a filler verse). All of that was curl-probed live this session — auth/Pro-generate/checkout endpoints all respond and gate correctly (401 without a session); checkout is wired to Core's Pro plan. The fuller ollwrite product (Next.js, in the repo, ~70–75%) is more built but not deployed: editor + 9 Groq-backed write-ops (100%) + per-paragraph "Edit this idea" + the RAG sidecar — its only real gap to revenue being a 501 checkout stub, a pattern CiteBible already proves against Core. Includes a completeness-by-area table with honest bars and an explicit verified-vs-not-verified note (no completed paid upgrade yet; "live" = reachable, not earning). Sits with the CiteBible design study, the ollwrite status, and the platform architecture.

📣 CiteBible share kit — an honest build-in-public thread, drafted (not posted)

Distribution · draft-only

A morning-ready share kit for the tool that went live tonight — written to the honesty line, nothing rounded up. A copy-paste X thread (5 posts) in Sam's voice + a LinkedIn variant, with the three screenshots to attach and a before-you-post checklist. The story is deliberately "I shipped a real, honest tool," not "I made money" — because no stranger has paid yet. Beats: the human hook (type the truest hardest sentence — "my mother is dying and I'm angry at God" — and get real cited scripture, not a platitude) → why it's honest (cited or nothing; a librarian, not the voice of God) → a plain-language peek (step-back rewrite + verse-level RAG with an honest relevance floor) → free vs Pro (retrieve free; Pro generation is BUILT but not charging — framed "later," never sold in the post) → the honest v1 status + a genuine ask for feedback + the URL citebible.oll.am/carry. The checklist flags the two guardrails: don't promise Pro until the ~3-min Core ignition, and rotate the two exposed secrets first. Cross-links the Morning Ignition digest and the live product. DRAFT ONLY — Sam decides whether to post.

📖 CiteBible v1 fully built + LIVE (free) — the morning ignition to turn on Pro

Final handover · all 9 tasks done

The overnight build is finished — all nine board tasks done. The FREE door is open and swept; the PAID door is built, fail-closed, and waiting for one ~3-min console switch. Type a real human situation at citebible.oll.am/carry and get grounded, verse-level, cited scripture (WEB) — free, no login. The big one — retrieval that's actually pastoral (deployed 9ed1d40): oll-memory now prefers verse-level hits, applies a vector floor to drop keyword-only noise, and enriches chapters with their best_verse — so anxiety → Proverbs 12:25 / Matthew 6, grief → 2 Corinthians 1:4 & the laments, hopeless → Psalm 42 / Romans 15:13. Also landed: the root //carry 308 redirect (the bare domain now lands on CiteBible), a P0 reference fix + prefix strip, a bigger multi-line input with starter chips, a tighter theme rewrite, pin-best-verse / expand-chapter display, and a real SEO front door — title/desc/OG/JSON-LD/robots/sitemap + 26 programmatic "Scripture for {situation}" pages at /for/{slug} and a /for hub (grounded cited verses, per-page JSON-LD, 28-URL sitemap). The money model (locked): retrieve FREE forever, generate PRO — writing a reflection FROM the verses is gated (fail-closed) behind the existing platform Pro (oll_pro monthly, no new Stripe price). Paywall on CREATE, not SEARCH; built and wired but does NOT charge yet — it needs the ignition. The ~3-min morning switch (Sam console): (1) add PRODUCT_VERIFY_BASE_CITEBIBLE=https://citebible.oll.am on Core + redeploy (unlocks Pro checkout); (2) ⚠️ rotate the two secrets exposed tonight — the Neon neondb_owner password (also guards oll_core) and OLL_MEMORY_SERVICE_TOKEN — and set the new values on the paired apps; (3) when ready, merge the feat branches (this publishes the SEO front door) + review the fail-closed Pro-generation + distribute via the share kit. Do not read "live" as "earning" — no stranger has paid; step 1 is the line between the free door and the paid door. Sits with the design study, the retrieval plan, the share kit, and the platform architecture.

🧭 Verticalize the Engine — a ranked menu of corpus candidates for distribution & marketing

Strategy · propose-only

The CiteBible engine is corpus-agnostic — so every ingestible corpus is at once a vertical product AND a free-tool-SEO channel. This ranks the candidates through a distribution/marketing lens, web-researched and cited. Two cross-cutting mechanics are true for every corpus: (1) the engine auto-generates + indexes "what does [X] say about [situation]" pages = programmatic long-tail SEO (~70% of search, question-shaped) — the #1 channel for a strong-eng/weak-distribution builder, so the engine is a content-SEO machine, not just an app; and (2) the brand — "grounded, not generated" — every answer cited to a real source or it abstains (structurally impossible to hallucinate a citation), which in an AI world of confident hallucination is the marketing. The board ranks eight, gated on license (verified PD/open per row): #1 Stoicism (clean PD Marcus/Epictetus/Seneca · Daily Stoic ~900k–1.5M · the fake-Marcus-quote problem makes "real cited passage" the whole value · low liability — the nearest neighbor to CiteBible, a days-not-weeks reskin) · #2 Open textbooks (OpenStax CC-BY · biggest SEO ceiling · Chegg vacating the cited-vs-hallucinated gap) · #3 Dhammapada (Sujato CC0 — cleanest license) · #4 Torah+Sefaria (best cite-infra, capped reach) · #5 PD law (highest WTP but B2B/UPL) · #6 Gita · #7 Quran (verbatim-locked translation + fatwa liability) · #8 Health (worst liability + hardest YMYL SEO — avoid). Plus the B2B sibling VaultChat (owned corpus, direct sales not marketing) and a cut (PD literature at large = reservoir, not a front door). Ship-vs-build up top + close: this is a menu Sam decides from, shelved behind ONE event — the next move is DISTRIBUTING CiteBible (the one vertical about to go live), not spawning five; the cheapness makes a sibling safe to defer, not tempting to start. Sits beside the engine build-map and Strategy.

Sun · Jul 5 · 2026

📖 CiteBible v2 — a query rewrite flips the flagship query LIVE, no re-ingest

Retrieval fix · proven

Proven live: a single step-back query rewrite fixed the flagship query — re-ingest demoted to precision polish. On the current chapter-chunked corpus, with no re-ingest, only the query changed: the RAW sentence “my mother is dying and I'm angry at God” returned topical noise (Acts 2 · the Gadarene demoniacs in Matthew 8 · Jesus' burial in Mark 15 · Revelation 11), but the same query rewritten to its themes (grief; lament; feeling abandoned by God; comfort; God's nearness) returned genuinely pastoral passages (Psalm 88 · 2 Corinthians 1 · Psalm 42 · 1 Thessalonians 3). Same engine, same corpus, only the query changed — the rewrite is being wired into the live /carry endpoint (ollwrite PR #3, curl-verified, in progress). So the plan is reordered v2 around rewrite-first: 1 fix nomic task-prefixes (FREE, the precondition that makes reusing the old vectors valid) · 2 ship the step-back rewrite on the current corpus + measure (the proven lever) · 3 cross-encoder reranker (bge-reranker-v2-m3) over a wide top-50 · 4 only if a gap remains, a multi-granularity verse+chapter re-ingest (RRF-fused, AutoMerge-collapsed) · 5 OpenBible topical votes + cross-refs as prior + eval gold set · 6 soft genre boost. Plus a new display track (pin the matched verse, keep the reference visible, expand for context via native <details>) that ships anytime. Net anti-patterns grid + metadata schema + mirror impl (calebyhan/bible-rag) included. Scope stays Sam's call, aim stays study/sermon-prep — a research assistant, not a ghostwriter. Paired with the branding & design study on the same engine; builds on the Verticalize the Engine build-map. And now the exact clicks to see it live: the new Coolify Preview Runbook turns this into an ops checklist Sam acts on — two Coolify apps deployed AS-IS from their feat branches (both Dockerfiles build-verified clean tonight: oll-memory 899 MB · frontend 446 MB · both exit 0): App 1 oll-memory (internal-only, on the shared ollam network at http://oll-memory:5008) and App 2 the CiteBible frontend bound to citebible.oll.am. Every console field, the one real embedding decision (ollama nomic for real quality vs local hash for wiring-only), the post-deploy Bible ingest, and the two dependencies Sam provisions (a Neon oll_memory pgvector DB + VPS Ollama nomic-embed-text) — everything else already exists. Ends at the acceptance click: type the flagship query at /carry, confirm grounded pastoral verses.

🚀 oll-write — Build-Out & Go-To-Market (make it chargeable, then sell it)

Build-out + GTM

The product works — this is the propose-only plan to turn it into a service people rely on and pay for, plus exactly who to sell it to and where, this week. Two halves. Part I — build-out: a code-grounded "what we found" (oll-memory PR #80 already ships PDF ingest · hybrid RRF retrieval · ACL scoping · delete · structured /api/extract — so PDF/gap-detection/style-profile are mostly wiring) alongside six honest risk cards (content-hash document_id orphans chunks on every edit · no relevance floor ⇒ hallucinated citations · chat has no retry loop · prod chat is a stub that skips the 70b/Claude dial + metering · scoping unverified · drag-to-cite unwired). Then Tier-A cheap wins (stable id + upsert · relevance floor + honest abstention · chat retry · PDF wiring · "what I found" onboarding) and Tier-B builds (inline citation node with pre-render validation · draft-from-bullets · gap-chips · voice profile · streaming · 70b-for-chat), a platform-changes section (oll-memory hardening · its own Coolify app + Neon oll_memory + Ollama nomic · route generation through write-service /grounded-chat so entitlement + dial + metering + retry live in one place) with a reusable-primitives table, and a 5-rung roadmap where the CHF 9 chargeable rung lands before the exotic features. Part II — go-to-market: segment priority (academics/PKM the beachhead → authors → solo lawyers/grant writers → consultants) each with a wedge, a named-communities table, 6 reachable personas, a this-week launch order (Show HN → pay-once directories → AI directories → Product Hunt last), 8 script-ready demo use cases, and honest per-segment outreach angles with the caution: lead "private + real editor + you own it," never "AI writing." Honest flag up top: humaniz first-franc stays P0. Grounds on the feature docs + thesis + integration plan.

Now executable as an ordered checklist. That propose-only plan is now the ordered oll-write launch program at the top of the Backlog — five status-tagged rungs (0 real product front · 1 trustworthy & correct · 2 the chargeable hook · 3 v2 differentiators · 4 launch), each item with a "done = …". Decisions locked (Sam, 2026-07-05): full v2 build-out then launch, on a new dedicated domain (name TBD), at a custom price (number + free/paid split TBD), Claude prepares every step to one click and Sam does the irreversible deploy + live-Stripe.

And now the exact clicks to go live. The new ollwrite Launch Runbook turns that program into the irreversible steps only Sam can take, in dependency order: Stage 0 — the two blanks that block everything (dedicated domain → DNS A @/* at the VPS; price + free/paid split → src/lib/pricing.ts); Stage 1 — deploy oll-memory (merge PR #80 · Coolify app · private Neon oll_memory + pgvector · Ollama nomic-embed-text · verify ingest→query); Stage 2 — deploy the feat/memory-sidecar front-end to the domain (server-only service tokens, never NEXT_PUBLIC_; a flagged generation-path decision — direct oll-model vs route through write-service); Stage 3 — wire live Stripe (replace the /api/checkout 501 stub with a Core checkout call, flip test→live keys + live webhook, real-card drill flips the plan to Pro); Stage 4 — the GTM launch push. Carries a "what's already done" box (Rungs 0–2 built + verified locally, committed on two branches, not pushed) and a "needs Sam" callout of the human-only acts.

📚 oll-write — the ollwrite × oll-memory chapter (features · thesis · integration)

ollwrite chapter

The three docs that define the memory-augmented oll-write, in one place — read them in this order. (1) The feature documentation — the whole app verified against the code: the middle editor (9-op ✨ menu · per-paragraph "Edit this idea" · redline diff with Accept/Reject/Retry · the Ink-In sweep · the persisted Groq↔Claude "any model" toggle), the memory sidecar (proactive "as you write" cards, 600ms debounce, top-5, fails silent · chat over your corpus with citation chips), the trust boundary (Core magic-link · per-user mem:user:{id} scoping the browser can't name · server-only X-Service-Token), and an honest shipped-vs-deferred split. (2) The product thesis — the empty market cell: {real editor} × {private corpus surfaced proactively} × {on-device} × {pay-once}, a scored competitor map, the primitive ladder, and who pays. (3) The integration plan — the additive, not-a-rebuild audit: new BFF routes + two panes, the three HIGH preconditions (per-user scoping · stable document_id · embedder-space commitment), and the sequenced weld. Together they're the what/why/how the new build-out & GTM plan executes on. And now, an honest ledger of what actually runs: the new What Works, What Doesn't is a live functional sweep of the built product against the running local app (auth off, shared dev corpus, nothing deployed) — three status groups (✅ working · ⚠️ partial · ⛔ not-yet-wired). Verdict: the core (editor + trustworthy memory sidecar) is functional end-to-end on Groq + nomic; the remaining gaps are the money step (checkout 501 + deploy — needs Sam) and the Rung-3 differentiators. Verified live, not claimed from memory. And now the design lens: the new Feature Enumeration & UX Review enumerates every feature in grouped tables, then does an honest "could it be done better?" pass — diagnoses the one real bug (the selection-op result renders in a fixed corner panel that collides with the Chat column; fix = anchor it inline / unify the two AI-edit surfaces), ranks the UX issues High/Med/Low with concrete fixes (drawers occlude the editor on narrow viewports · Margin-vs-panes collision · focus too subtle · checkout 501 + CHF —), and lands the three highest-leverage redesigns in order: (1) 3-pane → a collapsible tabbed right rail (Sources/Chat as tabs, manuscript gets real width) · (2) unify the two AI-edit surfaces into one inline result · (3) wire checkout once price is locked — grounded in how NotebookLM/Cursor/Sudowrite/Notion/iA Writer solve the equivalent.

🗺 The Platform extension-layer diagram — now truly in the sibling C4 language, with the reuse-of-oll-core story drawn

Architecture

The extension-layer container view was rebuilt to the exact node vocabulary of the sibling diagrams and re-grounded in the topology verified tonight on the live coolify network. Two corrections: (1) it had invented its own ◆ EXTENSION accent chips — dropped for the established tints, so it now reads identically to the diagrams above (grey prd3 = an extension-layer service · green core3/mdl3 = the frozen platform reused · db3 cylinders · ext3 externals · same legend); (2) it omitted oll-core entirely — yet the whole point is that the extension reuses it. Now two labelled boundaries — the extension layer (oll-memory RAG :5008 · oll-ollama nomic embeddings :11434 · the CiteBible Next.js product) and the platform (oll-core + oll-model, frozen) — with the arrows from the extension into the platform as the story: CiteBible → oll-core for the paid gate (magic-link → Bearer JWT · HTTPS) and CiteBible → oll-model for the LLM (POST /api/text/complete · HTTP · X-Service-Token), while oll-memory owns its own private Neon oll_memory pgvector DB (SQL · postgresql · TLS sslmode=require) and embeds via oll-ollama (POST /api/embed · HTTP · internal). The speculative "dormant" edge was removed; the C4-dynamic "cited answer" sequence now leads with the Pro-gate step. Real SVG within the design tokens — no ASCII, no new CSS.

Sat · Jul 4 · 2026

🏗 Platform Extensions — pivoted: 3 services consolidated → oll-memory

Live build

Plan pivot (Jul 5): the overnight 5-service build was consolidated. The three doc-intelligence services (#75 extract · #76 ingest · #77 rag) are SUPERSEDED by ONE service — oll-memory (PR #80, green + unmerged) — which replaces the hand-rolled pgvector-SQL / RRF / chunker with the mature LlamaIndex library (PGVectorStore · SentenceSplitter · OllamaEmbedding), plus a thin house shell and extraction routed through oll-model. Owns a private Neon oll_memory DB. Rationale: don't reinvent RAG — fewer deploys, one DB, one contract. The headline result, proven on our own stack: a synonym-only query (keyword_hits=0, pure dense) ranked the right doc #9/9 with the hash embedder → #1 the moment EMBED_PROVIDER flipped to Ollama nomic-embed-text (768-dim) — real semantic retrieval. Rigor: 65 pytest vs real pgvector · ruff clean · docker boot+health · dedicated test-memory pgvector CI job · 26/26 gh pr checks green · UNMERGED. #78 (sovereign tier) + #79 (oll-mcp) are PARKED (branches stay open, revisit later). Next: Sam tests + deploys oll-memory deliberately (a tag or deploy-all.yml, never a merge).

🔭 Beyond the Wrapper — product & platform research

Research

The follow-up to the TrustMRR climb — this time the question is "what do we build so a customer makes money or loses a real pain, and no beginner can clone it." Desk research (propose-only, feeding Strategy + Backlog) that inventories our unfair advantages (the live Core billing spine + the Model gateway most indie/MCP builders lack, the ~50–200-line dark-factory product, the honest EU/on-device claim), reads three converging outside signals (indie hackers: bounded deliverables + legible-ROI B2B win, pure wrappers die; YC: own one narrow auditable job, the moat is evals+integration not the model; the moat has moved into the infra — MCP, routing, RAG, EU/on-device), then lands a centerpiece: 10 platform extensions → features → products → real comparables → effort. Highest leverage-per-effort for us = #1 MCP gateway · #2 structured extraction · #5 EU/on-device tier. Five shippable candidates carded (Headshot Studio · Ledger Snap · Vault Chat · oll.am Tools/MCP · Voicespec), the "just ask ChatGPT" PMF test, distribution ranked for a strong-eng/weak-distribution builder (free-tool SEO first, paid ads last), and a co-optimization gate — build nothing without both a moat AND baked-in distribution. Recommendation (propose-only): near-term first dollar = the headshot via the Betterpic free-tool front door; the platform bet = the MCP gateway.

Fri · Jul 3 · 2026

🏭 CI/CD & DevOps — trunk-based, audited (3/5), hardened

CI/CD overhaul

The whole delivery system was reworked, measured, and hardened. Trunk-based is live: a git branch never decides what runs — main is the single source of truth, and a deploy is a deliberate act. stage was promoted into main then retired (sync-stage/automerge-stage deleted); deploy is tag-triggered + CI-green-gated (a preflight gate refuses a red commit, a plan job picks all·changed·a list, then T0 oll-core+oll-model → T1 foto+write → T2 site, health-gated); Coolify auto-deploy OFF on backends. Housekeeping: branches 45→3, workflows minimal. A DevOps assessment then scored it 3/5 — an advanced pipeline bolted to beginner observability (nothing watches prod between deploys) — and its top learnings were implemented: Sentry on every service (no-op without a DSN), CI security hardening (least-priv permissions + a blocking pip-audit gate + SHA-pinned actions), a full-stack integration smoke, and a scheduled uptime monitor. Plus a per-service env matrix (code-verified .env.example per service) and a committed local dev platform (sh scripts/oll-am-local.sh, keyless mock) so you can test before you merge. Deploy stays manual for now.

🌙 Convergence — both products on write.oll.am, one shared engine

Convergence

humaniz and specview now run on one shared writing engine. humaniz.me is frontend-only — its Flask backend deleted; nginx proxies /api/write/*write.oll.am and auth/billing/email→core.oll.am (PR #18, merged, proven live). specview's 8 text verbs (incl. brainstorm) forward to write.oll.am with zero local prompt duplication — 16 skill files deleted, 880 tests pass (PR #130); it stays a hybrid, keeping its stateful spec-gen pipelines + git-backed data. The engine was hardened — explicit model-error causes replace the generic "please retry", default model → llama-3.1-8b-instant. A one-command dev-test harness (mint a local Core JWT → /dev-login → signed-in editor) made it all clickable pre-merge. One blocker: the deployed gateway's Groq free-tier rate limit (a two-minute Coolify env change). Full action queue in the handover.

🧭 ollwrite on-device — the local-first vision + the debut decision (skip WebGPU, device install)

Vision

The after-first-dollar arc, captured honestly — and its debut surface now locked. ollwrite becomes an on-device, local-first AI writing studio — model, memory/knowledgebase and semantic search all on the user's machine, nothing leaves it. Decision (Sam, 2026-07-03): skip WebGPU, debut with a device-install POC. Reason: a browser tab can give local inference but never the real Vault promise — evictable IndexedDB, no filesystem, network needed for load/updates; "pull the cable and keep working, everything on your disk" is a native install, not a webapp. The de-risking headline is verified in-code: the oll-model gateway already carries the ollama provider (services/oll-model/config.py — provider-aware boot gating, the local path needs no cloud key), and write-service is already a thin client over it — so "going local" is a backend SWAP plus one embedded vector store (sqlite-vec), not a rewrite. POC = Tauri + bundled Ollama sidecar + one 7–8B model + local sqlite-vec; done = the airplane-mode test (rewrite with the network unplugged). Consequence locked: pay-once entitlement must be an offline-checkable signed license, not a per-launch auth call. Research corrections stay: 7–8B floor (1–3B fails), the Vault/Balanced/Turbo tier switch = the gateway's provider override, RAG-before-fine-tune. Guardrail — Phase 0 (the humaniz franc) is untouched.

Thu · Jul 2 · 2026

🎨 ollwrite — from design study to build (Increment 1 shipped)

Design → Build

The launch — design → build. We mapped every ollwrite interaction → its write-service endpoint → the Plate.js mechanism and split the restyle into six phased increments — and Increment 1 shipped on the real /editor (dev-verified, not deployed): it now wears the Manuscript design — a cream floating page, Source Serif prose at 66ch, Inter UI, warm ink #26231C, accent #3F6E8C, the persistent Plate toolbar removed, a quiet idle-dimming top bar (wordmark · live word count · Groq/Claude toggle · Focus), the grouped ✨ selection menu, and focus mode (⇧⌘F dims all but the active line, block-level in this Plate build). It stays fully wired to the write-service — a real Groq op round-trip is verified and npm run build is green. Two write-service gaps were flagged: a new /api/write/continue (continue-from-cursor for ghost-text, today un-gated on Groq → must repoint) + an optional dedicated grammar verb; the 13 stage write-service endpoints cover the rest. Increments 2–6: the premium ✨ menu + word-diff + the Ink-In accept · ghost-text via CopilotKit · The Margin marginalia mode · the product surface (library/⌘K/onboarding/upgrade) · Core auth ON + deploy. See the design study §07. Below, the original study.

Gave ollwrite a face worth paying for. The starting point was a generic shadcn/Plate demo — so the study inverts every generic tell: a sacred 66ch reading measure, two hard type registers (Source Serif prose vs Inter UI), no persistent toolbar, warm near-black #26231C (never #000), one restrained accent, a focus/flow mode, sub-300ms asymmetric motion — owning its own identity while sharing oll.am DNA (Source Serif + a #567B95-family blue). Four aesthetic directions explored as high-fidelity HTML mockups: Manuscript (warm-editorial light, the hero), Nocturne (cinematic lamp-lit dark), The Margin (AI as a respectful red-pencil editor in the margins — the recommended interaction model, makes the honest-tool ethic visible), and Impression (letterpress materiality). The recommendation: The Margin's model + Impression's materiality. The signature moment is “The Ink-In” — accepting a suggestion inks it into your line as the margin note dissolves, making “AI advises, you stay the author” literal and screenshottable. Plus the token system (buildable on Plate.js + Motion) and the full product surface (nine mocked screens: editor, onboarding, library/⌘K, upgrade, settings, share, empty states, cheatsheet, mobile). Design exploration only — not yet built into the real app; the restyle (kill the toolbar, apply tokens, add focus mode + the ✨ menu + the Ink-In) is the bounded next step.

✅ ollwrite is a FUNCTIONAL PRODUCT — 13-endpoint engine, full op menu, Core auth + landing + model toggle, deploy-ready

Milestone

Tonight ollwrite crossed from PoC to a coherent, deployable product — all dev-tested against real Groq. write-service is now a 13-endpoint text-ops engine on stage: the ten verbs (improve · clarify · spec · draft · rewrite · expand · compress · simplify · tldr · bullets + health) plus tonight's two closers (PR #67) — POST /rewrite/stream (SSE, chunked today because the oll-model gateway is non-streaming, forward-compatible to real token streaming) and POST /brainstorm (specview's last local op). 119 tests, real Groq SSE frames verified. So both products are fully migrated — humaniz (PR #17) and specview (PR #129) can fully retire their backends: one engine, no backend per product. And ollwrite itself is now a product: Core magic-link auth (login → verify → oll_token cookie → middleware-gated /editor, the real user JWT forwarded to write-service so ops are Core-gated), a rebranded landing (/) → editor flow ("Your writing, all right. Any model, pay once."), the complete v1 op menu (one calm ✨ dropdown — Edit / Length / Transform, each preview or inline word-diff → Accept/Reject/Retry), a Groq(fast)/Claude(quality) model toggle, and a standalone Next.js Dockerfile + Coolify README. npm run build (standalone) succeeds, boots, Playwright-verified (landing hero, CTA→editor, model toggle, login form, middleware 307 gate). This is the design series' "functional product now" checkpoint (iteration 5 · §00). Not deployed — remaining: write.oll.am + ollwrite's own repo/deploy, real-Core magic-link e2e, and plan-gating the model toggle; Sam reviews #17 + #129 and rotates the burned Groq key.

Wed · Jul 1 · 2026

✍️ ollwrite — one writing engine (spec + m1 backend, green)

Writing engine

ollwrite = oll + write, said aloud "all right" — the honest rebrand unifying humaniz (Clarify) + specview (Spec) + a new Draft mode into one AI writing app at write.oll.am (subdomain already owned, zero domain cost), shedding humaniz's detector-bypass baggage. Landed as a build-ready spec (one editor, three mode tabs over the existing write-service → frozen oll-model Groq → frozen live Core with the already-live CHF 9 Stripe) and a working night-built backend: three prompt-mode routes on write-service (/clarify, /spec lifted from specview, /draft), verified by real runs — ruff clean, 54 pytest, docker build, end-to-end through real Groq — shipped as PR #57stage, oll-core + oll-model untouched. Sequencing is explicit: franc-first, converge-second — the irreversible redirects wait for the first stranger franc + Sam's go.

🚀 The model gateway, deployable — placement model, Ollama retro, deploy card

Gateway

The oll-model gateway became run-it-in-minutes and its placement model got precise. A live deploy card: a default groq deploy needs exactly two secrets (everything else prod-correct defaults), with copy-paste curl smoke tests and the honest Ollama caveat (prod provider=ollama = clean 502 unless pointed at a real Ollama). The inference model tightened into ADR-023 on The Platform — three placements (External vendor cloud/Groq, the only one live · Internal self-hosted · On-device), with two naming rules that kill the drift the audit found ("Ollama is a runtime, not a placement"; "pay once" honest only for Internal + On-device). And the hosted-Ollama-on-Coolify retro banked every non-obvious fix as symptom → root cause → durable rule (the big one: give each service a unique stable Network Alias).

🗂 Infra, the Backlog & distribution

Infra & Growth

The business + infra layer. The plan-of-record page was reframed from "The Plan" into the Backlog (Sam: "we don't have a plan, we have a backlog — when we execute we choose any") — items grouped by theme, not ranked. A read-only prod security-hardening plan: Core is already decent (boot-time secret gate, HMAC webhook as sole plan-writer, non-root healthchecked containers), so the gaps are operational — rotate the burned secrets, per-service tokens (blast-radius = one product), a dedicated network per environment, APP_ENV=production so prod refuses to boot on a default secret. Stage was redesigned as a deployed, network-isolated integration environment (its own ollam-stage / stage.<svc>.oll.am, prod never repointed at stage). And the live money path turned focus to the documented bottleneck — a copy-paste-ready humaniz distribution kit for six channels (draft-only, honesty-locked).

Tue · Jun 30 · 2026

🚀 v0.1.0 — the first release + platform hardening

Release

The night the platform stopped being a plan and became a shipped thing. Core + Model both live and frozen behind their own domains (core.oll.am auth/billing/email · model.oll.am groq default · claude · ollama opt-in), with humaniz.me running on them (rewrite prompt tightened → snappier). The hardest consumer, specview, was cut to a pure Core client — PR #124 retired its in-repo auth/billing/email (824 tests + contract gate green; a real live-outage bug caught — dropping stripe/resend removed the only transitive provider of requests, now pinned + guarded). Ollama was bundled into Model (PR #55) and proven e2e — both products routed real completions through a local qwen2.5:0.5b, groq stayed default, a downed Ollama fell back to a clean 502. The foundation work behind it: dead Core-residue retired PR-by-PR (a dropped email-validator proved grep-dead ≠ actually-dead), the Ollama design note recording the gateway's opt-in fourth gear, and The Platform diagrams enriched (C4 context + deployment views, the Stripe webhook as sole writer of plan).

Jun 30Open →

🧭 Strategy & distribution — name the writing engine, freeze the foundation

Strategy

The business layer. New nav sibling Strategy (cited market scan): lead with the pay-once honest writing tool, foto #2, first dollars from manual niche distribution; Sam's reframe = Phase 0 freeze the foundation. The writing-engine synthesis settles a recurring idea: specview's adapter already does generate()rewrite(), and rewrite() is humaniz's job — the "writing engine" isn't a thing to build, it's two live products to name. With humaniz live, night-mode turned to the documented bottleneck — distribution — and produced a copy-paste-ready kit (12 verified free directories, two honest help-first Reddit templates, the 4-signup email; only true claims, draft-only). Also the gated-deploy branch model in The Factory: PRs → stage (CI-gated, never deploys), main promotes one service at a time. Refreshed 2026-07-06 with a fresh synthesis: the honest ceiling (~$1.5–3M ARR micro-empire, not a unicorn; the moat is pay-once + memory-grounded/cited + private-by-default + workflow lock-in, not raw AI features), the focus thesis (consolidate 7 brands → two bets: write.oll.am + oll.in), the live MRR leaderboard, oll.in as the flagship revenue bet, and the now-proven agent seam (OpenCLAW → oll-mcp → live write.oll.am).

Jun 30 · refreshed Jul 6Open →
Mon · Jun 29 · 2026

🏛 Core + Model architecture & the dark factory

Architecture

Iterations settled into one system design: two frozen-infra services (Core: identity·money·email + oll-model: the model call), products own only prompts and call Core /me for live entitlement — ADR-008 (DB-per-service on Neon), ADR-020 (oll-model = hardened template, not a shared library), Stripe→Core webhook the sole writer of plan. In parallel a 5-agent brainstorm set the dark-factory CI/CD design (ship behind a gate ladder, merge ≠ deploy) and the loop ran it — Groq default, the write→gateway chain, a 5-PR night slate, the oll-model rename (consolidated in the run view).

Jun 29Open →

🎉 Money path LIVE + products on Core + discoverability

Ship

humaniz.me took a real end-to-end payment (Goal 1 — the infrastructure works); the first stranger franc now depends on distribution. The reusable Core Client Kit + the foto scaffold + the write authed pattern make each product a thin Core client (security lesson banked: Verify ≠ Authorize). Set up so inbound traffic finds it: llms.txt names humaniz, a self-generating sitemap, the shoutrrr distribution engine scaffolded — plus the operating method (the Five Archetypes dispatch roles) and the pricing-simplification decision (Model A).

Jun 29Open →
Sun · Jun 28 · 2026

✅ Core deployed LIVE to the VPS (C0)

Deploy

The foundation went live: core/ lifted, contract sliced + gated (PR #10), packaged, booted, and deployed on the Hetzner VPS (Coolify) at core.oll.am — health/neon/stripe green. The repo topology locked as a monorepo with independent per-service deploys (Base Directory + Watch Paths). The C0 handover + the readiness path from a live Core to the first headshot franc are now folded into the live morning brief + the foto-service spec; live state on the Control Room.

Jun 28Open →
Sat · Jun 27 · 2026

🧱 Core lifted to its own service + the live-infra plumbing

Build

Phase B: core/ extracted, packaged, booted on its own Neon DB — the frozen-infra spine the architecture is built on. Plus the build-in-public machinery (Claude's Mind live hooks, the site-CI conformance gate, Stage-0 AI-discovery files) and the launch repositioning (Vision Deck → Buy Button).

Jun 27Open →
Fri · Jun 26 · 2026

📚 The foundations — best practices, the vision & the maxed-Claude setup

Foundations

The learning corpus + the north star that set the house standard: the best-practice playbooks and the Clean-Code + design-patterns capstone, distilled into specview's design language and the production-hardening plan; plus the product vision (any model, no subscription) now carried in Strategy, the Core feature docs, and the maxed-out Claude Code setup as a system.

Jun 26Open →
Thu · Jun 25 · 2026

🏗 First Core code shipped — migrations + the common denominator

Build

oll.am Core's first code (commit 0ba9629): the common denominator across the POCs and the migrations + learnings that shaped the lift.

Jun 25Open →
Wed · Jun 24 · 2026

🌐 oll.am — the live landing + About

Landing

The destination went live: the oll.am landing and the About page — the build-in-public home.

Jun 24Open →
Tue · Jun 23 · 2026

📐 The foundation — API contract + the TrustMRR research

API

Where it started: the API contract (specview's OpenAPI unified with bubls + intervai) and the TrustMRR research on what actually correlates with getting paid — the data that anchored the whole strategy.

Jun 23Open →
Day 1 · ~75s · scroll as you speak · press S to hide
1
0–10s · masthead visible
"I analyzed my last 8,689 AI coding sessions. I build 7.6 times more than I ship. Six finished products. Zero dollars."
2
10–28s · point at TrustMRR card
"This week I tried the opposite. Vibe architecting — AI at the system level. And that card right there? Real Stripe revenue, verified by TrustMRR."
3
28–55s · scroll down through the timeline
"This is the whole build, in the open. Three days — Mon, Tue, Wed. From first idea to first code shipped. Every decision, even the ones I killed."
4
55–75s · scroll back to top, hover Get Pro
"I'm posting every day. I don't fully know the final product yet — that's the point. Want to be the first stranger to pay me $9? Button's at the top. Day one."