The production platform for ObjectStack

AI can hold the whole app.
You control what ships.

ObjectStack keeps the whole application — data model, UI, workflows, and permissions — as typed definitions: a complete CRM stays under 150k tokens, small enough for AI to read and reason about in one context window. ObjectOS is the commercial production platform around it: teams use AI Build & Ask, review and approve changes, then deploy and operate with SSO, approvals, and audit — in our cloud or yours.

ObjectStack in 90 Seconds More videos on YouTube
One context window
A complete CRM is under 150k tokens
Human-controlled
Review and approve what ships
Production-ready
SSO, permissions, audit — cloud or yours

For AI-written enterprise software

Keep the systems that work.
Add a governed runtime for agents.

Enterprise AI does not need another rebuild project or another pile of generated code. It needs a compact target format agents can write, humans can review, and a runtime that keeps each change governed across legacy systems, new applications, and AI agents. Your objects, permissions, and flows are your open business ontology — versioned files you own, not an asset locked inside someone else’s platform.

ObjectOS connecting business data, applications, and AI agents
Unified business object layerConnecting applications, data, and agents

Platform capabilities

Start with the business model,
not a blank codebase

Read about AI and agents
  1. 01

    Give agents a business model

    Model customers, orders, equipment, cases, and approvals as objects agents can read, relate, and act on.

  2. 02

    Extend systems without replacing them

    Add APIs, permissions, workflows, and intelligence on top of databases, ERP, CRM, and custom systems.

  3. 03

    Generate metadata, not app code

    For typical CRUD and workflow software, agents write the compact ObjectStack definition; the open ObjectStack runtime derives tables, APIs, UI, and tools, then enforces permissions and audit, while ObjectOS handles production deployment and team operations. Less code to generate, less code to review.

  4. 04

    Enforce governance at runtime

    Reuse enterprise identity, permissions, approval queues, and audit logs so every agent action has a defined boundary.

AI build and agent operations

Let agents create the software.
Keep people in the review loop.

ObjectStack keeps objects, fields, workflows, permissions, actions, and UI as typed definitions agents can read and change. Its open runtime derives the database, APIs, screens, and MCP tools, then enforces permissions and audit on every call. Strict TypeScript, Zod schemas, and a validation gate catch structural mistakes before deployment. A complete CRM stays under 150k tokens — under 100k for the business logic, with the UI bringing the whole definition under 150k — so a coding agent can reason across the entire system and you can review the diff. ObjectOS turns that open foundation into a commercial production platform for teams: in-app AI Build & Ask, human approvals, SSO, deployment, and operations on Cloud and Enterprise; bring your own coding agent and MCP client on open-source ObjectStack.

View the AI security model
01

AI Builder

Cloud & Enterprise: describe a change in natural language. The in-app Builder generates objects, fields, views, and workflows, then routes structural changes for approval. On the open-source ObjectStack, your coding agent writes the same compact metadata diff instead of a full app codebase.

02

AI Ask

Cloud & Enterprise: ask questions inside the product, analyze business context, and trigger approved actions within the signed-in user’s permissions. On the open-source ObjectStack, query the same objects through MCP with your own AI.

03

Tools / MCP

All editions: @objectstack/mcp exposes objects, queries, and actions as policy-aware tools for Claude, Cursor, any MCP client, or a local model.

How it works

Turn business operations into
a structure agents can use

ObjectStack describes objects, relationships, permissions, workflows, and actions as unified typed definitions. Agents change a context-sized definition layer instead of regenerating application code; ObjectOS gives teams the review, deployment, and operational controls that keep every iteration understandable, approved, and governed.

Your existing systems
CRMERPDatabasesCustom systems
Model objects
OBJECTSTACK DEFINITION LAYER Objects · Permissions · Workflows · API · Audit
Govern execution
What runs on top
Business appsAI agentsAutomation

Security and governance

Keep data in your network.
Let AI work inside permissions.

ObjectOS can deploy and operate ObjectStack apps on your infrastructure. Business records, identities, audit logs, and files stay under your control; AI agents access objects through governed tools and inherit the signed-in user’s permissions.

Explore security and governance

Data residency

Connect your databases and storage. Unless you configure an external service, ObjectOS does not send telemetry, contact a license server, or transmit data back to ObjectStack.

User-scoped AI

Agents act as signed-in users and obey object, record, and field permissions, so they cannot see data the user cannot see.

Approval and audit

Structural changes go through a human approval queue. Reads, writes, tool calls, and permission changes can be written to audit logs.

Offline ready

Run in a VPC, on local servers, or in air-gapped networks with local models, internal identity, and your own secrets management.

Application templates

Start with working templates,
not a blank canvas

How it compares

Different from
the tools you know

Read the comparison

Latest insights

Practical thinking on AI-native software

Browse all articles
How to Self-Host an AI App Platform: ObjectStack from Install to Verified

How to Self-Host an AI App Platform: ObjectStack from Install to Verified

A walkthrough of self-hosting the open-source ObjectStack runtime: the compiled-artifact model, the database driver everyone misses, how to prove the install is correct, and what you are now on call for.

Build a CRM With an AI Agent: The Whole Build, Including What Broke

Build a CRM With an AI Agent: The Whole Build, Including What Broke

One complete CRM built end to end — scaffold, three objects, an approval flow, a permission set. 2,406 measured tokens, 54 generated API operations, and the four defects caught before a human reviewed anything.

How to Review AI-Generated Code: A Checklist for Metadata App Changes

How to Review AI-Generated Code: A Checklist for Metadata App Changes

A four-pass review order for AI-written app changes, worked on a real diff. The validation gate proves a change is enforceable; it never proves the change is correct. That third rung is the reviewer's whole job.

Next step

Start with the business data you know best.

Connect one existing system, define its key business objects, and let your agent ship the first governed AI-written application as a small metadata diff.

Learn how to connect existing systems