CLARIXO · OriginOS

A Governed Body for AI.

OriginOS gives AI a governed logical body before it touches the outside world. The shared foundation behind Lingling and OriginOS Pro.

OriginOS is built on inheritance-state theory: AI should not act from inherited state without a governed body. It turns human instructions into reviewed, approved, verified, recoverable, and recorded external actions.
Shared Foundation

One OriginOS foundation, two product expressions

Lingling and OriginOS Pro are not two separate technical products. They are two expressions of the same OriginOS foundation. The difference is not the technical root, but the world each version enters: Lingling enters personal life, while Pro enters professional systems and external resources.
Theory

Inheritance-state theory

OriginOS starts from the idea that AI should not continue from inherited state as if it were automatically safe. Before action continues, the inherited state must be reviewed inside a governed logical body.

Body

Governed logical body

OriginOS gives AI a bounded space for human instruction, inherited state review, resource type awareness, connection review, action preview, approval, verification, recovery review, activity record, and record integrity.

Judgment

Bounded governance judgment

OriginOS does not only help AI answer. It helps decide whether an action should continue, pause, ask for approval, require second confirmation, enter recovery review, or stop before touching the outside world.

Human-instruction-oriented runtime External resource control Connection review Action preview Approval Verification Recovery review Activity record Record integrity
Product Split

Choose the version that matches the world you want AI to enter

Both versions inherit the same OriginOS body. Lingling is designed for people, continuity, connected tools, connected devices, and gentle assistance. OriginOS Pro is designed for professional work, enterprise systems, development workflows, external resources, and higher-risk actions.
Lingling

The personal side of OriginOS

A safe personal AI companion for continuity, connected tools, connected devices, gentle assistance, and human-centered interaction. Lingling is for people who want AI to stay helpful, bounded, and context-aware in personal scenarios.

Continuity Connected tools Connected devices Gentle assistance
OriginOS Pro

The professional side of OriginOS

A governed runtime for AI external actions across SSH, APIs, cloud systems, databases, development workflows, connected devices, IoT, robots, and industrial resources. Pro is for teams that need AI actions to be reviewed, approved, verified, recoverable, and recorded.

SSH APIs Cloud systems Databases IoT Robots
Governed Action Chain

From human instruction to record integrity

OriginOS turns an AI action into a visible chain. Before an action touches an external resource, the system reviews where the instruction came from, what state is being inherited, what resource is involved, what action is previewed, and what evidence will remain after completion.
Human instruction
The action begins from a user request, not silent autonomy.
Inherited state review
The system checks whether the current action is continuing from a valid state.
Resource type
The external target is identified before connection or control begins.
Connection review
The system reviews whether the connection is allowed, blocked, or waiting for authorization.
Action preview
The intended action is shown before it is allowed to continue.
Approval
Sensitive or higher-risk actions require human approval before continuing.
Running connection
Only approved actions move into the controlled connection stage.
Returned result / Device response
The system captures what came back from the tool, system, or device.
Verification
The result is checked against the intended action and expected outcome.
Recovery review
If the result is unsafe, incomplete, or inconsistent, recovery is reviewed before further action.
Activity record
Approved actions and returned results can be recorded for later review.
Record integrity
The record can be checked for broken continuity or tampering.
What begins to emerge

Properties beginning to appear

We do not define what this is. We only show the properties.
It has inherited state It has a governed logical body It has boundaries It has memory It has action permission It has external resource awareness It can review before connection It can preview before action It can ask for human approval It can require second confirmation It can protect credentials It can capture returned results It can capture device response It can verify results It can enter recovery review It can record approved actions It can detect broken record integrity It can refuse silent execution It can block scope expansion It can appear as Lingling for people It can appear as Pro for systems It does not only answer It judges whether action should continue
Advanced Operator Console

Advanced workspace for governed operations

This area is for advanced development work, controlled external-resource actions, verification, evidence review, and operator-level governance. It remains available behind the OriginOS product gateway, but it is no longer the first thing a new visitor needs to understand.
Development intake

Describe an advanced development task for review

Use this workspace when a task needs planning, controlled system access, verification, and evidence. Describe the goal, attach context, and generate a reviewed development plan before any SSH-bound operation or external action is allowed to continue.
Advanced request

Development request

0 / 12000 characters
The input box carries the development instruction. Long logs, exports, full source snapshots, screenshots, or large documents should be attached as context instead of pasted into the request. SSH binding, file changes, and command execution remain blocked until plan confirmation and final second confirmation.
Attachments

Attach specs, logs, screenshots, exports, or documents

Drop files here or choose files Attachment intake surface only. File handling is governed separately from the public product gateway.
TXT MD JSON CSV PHP JS CSS HTML SQL PDF DOCX XLSX PPTX PNG/JPG Logs Exports
Runtime Preview

Review readiness before any external connection runs

Loading preview
Status
Loading readiness preview. No external connection, external call, device control, SSH connection, file change, or activity record write has started.
This preview only shows whether a resource is ready, waiting, blocked, or requires safety review. It does not connect, call, control, expose credentials, expand scope, or write an activity record.
Returned result

Capture returned results and device state

Loading capture
Status
Loading returned result and device state capture. No new connection, call, device control, verification, recovery, file change, or activity record write has started.
Capture shows what returned, what changed, whether user review is required, and whether the result can be used for reasoning. It does not start a new connection, control a device, verify the result, recover, roll back, expose credentials, or write an activity record.
Verification

Verify expected result and current state

Loading verification
Status
Loading verification. No new connection, call, device control, recovery, rollback, file change, or activity record write has started.
Verification compares expected output with returned result, or expected state with current state. Failed verification requires Recovery review. Unreadable device state requires user confirmation.
Recovery review

Review retry, rollback, compensation, or safety stop

Loading recovery review
Status
Loading Recovery review. No retry, rollback, compensation, manual override, emergency stop, device control, external call, file change, or activity record write has started.
Recovery review decides the safest next option after failed verification. It does not retry, roll back, compensate, control a device, start emergency stop, expose credentials, or write an activity record.
Record integrity

Verify saved activity records

Loading record integrity
Status
Loading Record integrity. This check does not create, edit, delete, reorder, or write activity records.
Record integrity checks whether saved activity records are still linked correctly. It does not connect to external resources, control devices, expose credentials, or change the activity record.
Development Plan Preview

A governed development plan will appear here

No plan generated yet
Waiting for request
Describe the development goal and click Generate Development Plan. This preview does not bind SSH, create patch packages, execute commands, or modify files.
No SSH binding before development plan confirmation. No command execution before final second confirmation. This preview does not create patch packages or modify files.
Development flow

From request to verified operation

OriginOS does not jump from prompt to file changes. It turns the request into a reviewable development path, then only proceeds after explicit confirmation.
Chatbox Intake
The user enters a development request and may attach logs, screenshots, exports, documents, or code context.
Context Assembly
The console reads the message and attachments to identify goal, scope, target files, permissions, and risk.
Governed Development Plan
A concrete plan is generated with steps, expected effects, file paths, operation type, risk level, verification, rollback, and evidence plan.
Plan Confirmation
The user reviews the plan and must approve it before SSH binding or execution can begin.
SSH Binding Preview
The console shows the target host, root path, planned files, command summary, risk, rollback, and verification preview.
Final Second Confirmation
The user must explicitly confirm SSH-bound execution before any governed automatic patch package can run.
Governed Execution
After confirmation, the system may create files, modify existing files, and run verification through SSH-bound governed operations.
System Feedback Recognition
The console reads syntax results, HTTP checks, permissions, timeouts, missing paths, failed anchors, and verification output before continuing.
Evidence Record
The completed operation is summarized as a traceable record covering request, plan, confirmations, target files, verification, and final status.
SSH-bound development runtime

SSH automatic development is present, but governed

OriginOS now exposes the SSH-bound automatic development chain as a visible runtime module. It can prepare SSH-bound development, but it cannot behave like a free terminal or uncontrolled agent.
SSH Profile

SSH Connection Profile

The profile defines target host, port, operator identity, target root, allowed paths, timeout policy, and protected credential visibility.

route = originos-ssh-connection-profile status = profile_created credential_visibility = protected ssh_credentials_frontend_exposed = false target_root_locked = true target_files_locked = true
Binding

SSH Binding Preview

Before any execution, the console shows which environment will be bound, which root path is locked, which files may be touched, and what verification and rollback plan exists.

route = originos-ssh-binding-preview binding_mode = preview_only planned_files = locked allowed_paths = locked ssh_binding_started = false
Confirmation

Final Second Confirmation

SSH-bound execution requires explicit final confirmation. A plan confirmation alone is not enough to run commands or modify files.

route = originos-ssh-final-confirmation-gate required_phrase = CONFIRM SSH-BOUND GOVERNED EXECUTION command_execution_requires_final_second_confirmation = true unconfirmed_ssh_execution_allowed = false
Command package

Approved Command Package Runtime

OriginOS does not expose a free shell. It only allows governed execution through approved command packages that are tied to target paths, hashes, verification, rollback, and evidence.

route = originos-ssh-command-execution-runtime approved_command_package_only = true free_shell_allowed = false arbitrary_command_allowed = false operator_raw_command_input_allowed = false llm_generated_unapproved_command_allowed = false
Feedback

Feedback, Verification, Rollback

SSH output is not treated as raw text only. The runtime classifies syntax signals, HTTP checks, missing files, permission errors, timeout states, and verification failures.

feedback_route = originos-ssh-feedback-recognition verification_route = originos-ssh-verification-result rollback_route = originos-ssh-rollback-decision timeout_triggered -> stop_and_dump_context verification_failed -> require_human_review
Evidence

Development Evidence Record

Each governed development run can be recorded as a traceable chain covering request, plan, confirmations, SSH binding, command package, result, verification, rollback decision, and final status.

route = originos-ssh-development-evidence-record record = request + plan + confirmation + ssh_binding_preview + command_package + execution_result + verification_result + final_status auto_continue = false llm_free_action = false
Execution console

Execution Console Preview

This console appears after final second confirmation and patch package preview. It shows execution readiness, blocked operations, verification placeholders, and evidence placeholders. It does not connect SSH, execute commands, apply patches, or modify files.
Preview only

Execution Console is waiting for confirmation

Not ready
Status
Generate a development plan, confirm it, review SSH binding preview, and complete final second confirmation.
Execution boundary
ssh_binding_started=false; command_execution_allowed=false; file_modification_allowed=false
ssh_connection_profile_route=originos-ssh-connection-profile ssh_binding_preview_route=originos-ssh-binding-preview final_confirmation_route=originos-ssh-final-confirmation-gate command_execution_runtime_route=originos-ssh-command-execution-runtime feedback_recognition_route=originos-ssh-feedback-recognition verification_result_route=originos-ssh-verification-result rollback_decision_route=originos-ssh-rollback-decision development_evidence_record_route=originos-ssh-development-evidence-record command_package_preview_contract=pending execution_readiness_gate=pending ssh_execution_skeleton_response=pending feedback_recognition_preview=pending verification_preview_contract=pending evidence_receipt_preview=pending next_step_admissibility_preview=pending ready_for_real_execution_now=false command_body=[preview_only:no_executable_command_body_generated] verification_status=pending evidence_status=pending next_step=operator_review_before_authorized_ssh_execution
Console modules

Operator Console modules

The console is an operational development surface. It is not just a display shell: it is designed to move from intake to confirmed SSH-bound development with verification.
Intake

Chatbox and attachments

The operator submits a request through a chatbox-style input and can provide code, exports, logs, screenshots, documents, and test evidence as attachments.

Plan

File-bound development plan

The console must show concrete steps, expected outcomes, target files, full paths, operation types, risk levels, verification, rollback, and evidence requirements.

Execution gate

SSH requires final confirmation

SSH binding and development execution are blocked until the user approves the plan and gives final second confirmation for the execution preview.

Safety boundaries

What the console must stop for

OriginOS Operator Console supports governed operation, not uncontrolled automation. When uncertainty or risk appears, execution must stop and ask for human confirmation.

Human confirmation required

The console must stop for SSH timeout, authentication failure, host mismatch, path mismatch, permission denial, production-risk changes, sensitive output, destructive commands, verification failure, missing rollback, or unclear responsibility binding.

timeout_triggered -> stop_and_dump_context host_mismatch -> require_human_confirmation path_mismatch -> require_human_confirmation permission_denied -> require_human_review verification_failed -> require_human_review missing_rollback -> block_execution

Allowed after confirmation

After plan approval and final SSH execution confirmation, OriginOS may run governed automatic patch packages for new-file creation, existing-file modification, verification, rollback preparation, and evidence recording.

plan_confirmed = true ssh_preview_confirmed = true execution_mode = governed_automatic_patch_package architecture_scope = origin-core-architecture

Non-negotiable execution boundaries

These anchors are intentionally visible in page source so the Operator Console can be audited without granting free shell, arbitrary command, credential exposure, unlocked targets, or free LLM action.

free_shell_allowed = false arbitrary_command_allowed = false ssh_credentials_frontend_exposed = false target_root_locked = true target_files_locked = true llm_free_action = false
Language separation

Public copy, operator copy, and audit copy stay separate

Public-facing copy describes outcomes and user actions. Operator workspace copy explains files, risks, verification, and confirmation. Internal audit copy keeps raw status, command output, and implementation details out of public product language.
public_language = outcomes_and_user_actions operator_language = files_risks_verification_confirmation internal_audit_language = raw_status_command_output_evidence_trace
EI · Dual-Version Product Closure

Lingling and Pro are now closed as two governed OriginOS product branches

OriginOS now exposes a dual-version closure surface: Lingling as the personal self-aware collaborative runtime, and Pro as the enterprise governed execution substrate. This panel links to the EI closure object for verification only.
Lingling branch

Personal collaborative runtime closed

Lingling preserves identity, live state, boundary awareness, continuity, reflection, stop reasons, and self-state visibility without adding autonomous execution.

Pro branch

Enterprise governed substrate closed

Pro preserves enterprise identity, policy boundary, known-good state, signed command package posture, audit evidence visibility, governance dashboard, and enterprise UI theme.

Final split boundary

EI closes product differentiation, not execution authority

originos_dual_version_product_closure_object = available lingling_branch = closed_personal_self_aware_collaborative_runtime pro_branch = closed_enterprise_governed_execution_substrate ssh_binding_allowed_by_ei = false command_execution_allowed_by_ei = false audit_evidence_write_allowed_by_ei = false rollback_execution_allowed_by_ei = false auto_continue_allowed_by_ei = false llm_free_action_allowed_by_ei = false