0x00 OO_INIT APPROVED OPS AUDIT:ON SECRETS:REFS
AI-Everything operator layer / audit ready

OpenOrange Operator Layer

OpenOrange turns AI infrastructure into private instances, runtime signals, reviewed workflows, approved operations, model usage accounting, billing visibility, and audit proof.

AI infrastructure states

// scroll reel
Instance
Runtime
Signals
Plans
Operator
Everything
AI - Instance

$ operator load operator instance

A private OpenOrange instance defines the profile, domains, local secrets, operator API, admin surface, and proof boundary.

01 AI - Instance
02 AI - Runtime
03 AI - Signals
04 AI - Plans
05 AI - Operator
06 AI - Everything
// product proof

One operator layer, one operational view.

The dashboard proves the AI-Everything layer is more than a slogan: users, agents, runtime health, observed-state snapshots, model routes, request traces, billing, privacy, and audit controls in the same operated surface.

surface state proof
users ownership + access Admin access, users, and instance ownership stay visible per private instance.
agents runtime status Agents, channels, runtime adapters, heartbeats, and last-known health stay tracked as operated surfaces.
observability health + drift Observed-state snapshots, health checks, drift signals, and operator events show what changed and when.
models tokens + cache Model routes, token usage, prompt-cache savings, and provider costs stay accountable.
billing tariffs + history Customer tariffs and historical model prices make usage explainable.
requests privacy + audit Request traces preserve actor, route, model, token, cost, and redaction state without exposing raw payloads by default.
audit plans + applies Plans, approvals, apply attempts, smoke checks, and rollback metadata stay tied to the instance.

OpenOrange system position

// system spec

Instances, runtimes, signals, plans, operators, and the governed path to everything else.

OpenOrange keeps the original operator-layer idea and makes the proof concrete: private instances, runtime adapters, dashboard signals, usage accounting, billing visibility, local secrets, and reviewed operations.

01

AI - Instance

Every operator layer starts from a private OpenOrange instance.

The instance profile makes the operating boundary explicit: host, local secrets, operator API, admin dashboard, release bundle, domains/TLS, and audit identity.

[instance][local profile][secrets][tls]
02

AI - Runtime

The runtime keeps execution; OpenOrange governs the operating layer around it.

Adapters can connect OpenClaw, Hermes, IronClaw, ACP, webhook agents, and future runtimes while sessions, memories, media, caches, overlays, and raw logs stay where they run.

[runtimes][adapters][channels][tools]
03

AI - Signals

Observability becomes operator-grade proof, not another loose log stream.

Observed-state snapshots, health checks, drift, request traces, model usage, billing attribution, redaction state, and operator events stay tied to the instance.

[health][drift][requests][proof]
04

AI - Plans

Runtime work becomes reviewable before it becomes action.

OpenOrange turns desired changes into reviewed plans with approval shape, plan hashes, smoke checks, rollback metadata, and audit records.

[plan][approve][apply][audit]
05

AI - Operator

The dashboard makes the system legible enough to operate.

Admins see users, ownership, agents, runtime health, heartbeats, drift signals, models, tokens, cache, billing, request traces, confidentiality mode, and usage attribution in one command surface.

[health][requests][models][audit]
06

AI - Everything

One governed layer across the AI system.

AI-Everything means the same operating contract across instances, runtimes, model access, tools, plans, approvals, usage, billing visibility, rollback, and proof.

[tokens][tariffs][cache][usage]
operator loop

Review runtime changes before they touch an instance.

  1. observe
  2. plan
  3. approve
  4. apply
  5. smoke check
  6. audit
// FAQ

FAQ

Frequently asked questions

OpenOrange is the AI-Everything operator layer around private AI infrastructure: instances, runtime adapters, model access, dashboard signals, reviewed plans, approvals, usage accounting, rollback metadata, and audit proof.

OpenOrange owns the operator control plane: instance profiles, observed metadata, model usage attribution, desired state, plans, approvals, provisioning jobs, billing visibility, and audit records. It should not turn live runtime state into Git state by default.

Secrets, sessions, memories, media, caches, runtime databases, overlays, and raw logs stay on the instance or runtime host. OpenOrange works with references, redacted observations, request attribution, reviewed plans, and proof.

OpenClaw is one runtime shape the operator layer can understand. The product idea is broader: adapters for agent runtimes, channels, tools, model routes, webhook agents, and future execution layers under the same operating contract.

Raw payloads do not need to become control-plane data. Request traces can preserve actor, route, model, token, cost, cache, redaction state, and audit context while sensitive contents stay local or redacted.

The operating model is plan-first: observe, validate, plan, approve, apply, smoke, and audit. Mutating work should require a stored plan, matching approval, plan hash, backups, smoke checks, rollback metadata, and audit events.

A private instance starts from an explicit profile: create the host boundary, seed root-only secrets, install the release bundle, validate the operator API and dashboard, then expand through reviewed plans.

Token values, provider keys, registry credentials, and channel credentials stay in local secret files or secret backends. OpenOrange stores secret references and audit context, not copied secret values.

Model calls should be attributable by actor, agent, model, route, request, tokens, cache behavior, price version, and customer tariff. The dashboard makes spend explainable while the operator layer keeps the billing proof tied to the runtime and approval history.

Send an OpenOrange operator-layer intake brief

Send an operator-layer intake brief.

Tell us what you want to operate, measure, protect, approve, or prove. This is a human-reviewed contact brief for now, not a live provisioning step.

intake:human no auto-provision reply required

Instance, agents, runtime adapters, dashboard users, usage or billing visibility, privacy requirements, approval path, rollout boundary, or audit requirement.

Best reply channel?

Where should we reply?

human review first