The production platform for ObjectStack
AI can hold the whole app.
You control what ships.
ObjectStack keeps the whole application — data model, UI, workflows, and permissions — as typed definitions: a complete CRM stays under 150k tokens, small enough for AI to read and reason about in one context window. ObjectOS is the commercial production platform around it: teams use AI Build & Ask, review and approve changes, then deploy and operate with SSO, approvals, and audit — in our cloud or yours.
- One context window
- A complete CRM is under 150k tokens
- Human-controlled
- Review and approve what ships
- Production-ready
- SSO, permissions, audit — cloud or yours
For AI-written enterprise software
Keep the systems that work.
Add a governed runtime for agents.
Enterprise AI does not need another rebuild project or another pile of generated code. It needs a compact target format agents can write, humans can review, and a runtime that keeps each change governed across legacy systems, new applications, and AI agents. Your objects, permissions, and flows are your business ontology — open files you own, not an asset locked inside someone else’s platform.
Platform capabilities
Start with the business model,
not a blank codebase
- 01
Give agents a business model
Model customers, orders, equipment, cases, and approvals as objects agents can read, relate, and act on.
- 02
Extend systems without replacing them
Add APIs, permissions, workflows, and intelligence on top of databases, ERP, CRM, and custom systems.
- 03
Generate metadata, not app code
For typical CRUD and workflow software, agents write the compact ObjectStack definition; the open ObjectStack runtime derives tables, APIs, UI, and tools, then enforces permissions and audit, while ObjectOS handles production deployment and team operations. Less code to generate, less code to review.
- 04
Enforce governance at runtime
Reuse enterprise identity, permissions, approval queues, and audit logs so every agent action has a defined boundary.
AI build and agent operations
Let agents create the software.
Keep people in the review loop.
ObjectStack keeps objects, fields, workflows, permissions, actions, and UI as typed definitions agents can read and change. Its open runtime derives the database, APIs, screens, and MCP tools, then enforces permissions and audit on every call. Strict TypeScript, Zod schemas, and a validation gate catch structural mistakes before deployment. A complete CRM stays under 150k tokens — under 100k for the business logic, with the UI bringing the whole definition under 150k — so a coding agent can reason across the entire system and you can review the diff. ObjectOS turns that open foundation into a commercial production platform for teams: in-app AI Build & Ask, human approvals, SSO, deployment, and operations on Cloud and Enterprise; bring your own coding agent and MCP client on open-source ObjectStack.
View the AI security model →AI Builder
Cloud & Enterprise: describe a change in natural language. The in-app Builder generates objects, fields, views, and workflows, then routes structural changes for approval. On the open-source ObjectStack, your coding agent writes the same compact metadata diff instead of a full app codebase.
AI Ask
Cloud & Enterprise: ask questions inside the product, analyze business context, and trigger approved actions within the signed-in user’s permissions. On the open-source ObjectStack, query the same objects through MCP with your own AI.
Tools / MCP
All editions: @objectstack/mcp exposes objects, queries, and actions as policy-aware tools for Claude, Cursor, any MCP client, or a local model.
How it works
Turn business operations into
a structure agents can use
ObjectStack describes objects, relationships, permissions, workflows, and actions as unified typed definitions. Agents change a context-sized definition layer instead of regenerating application code; ObjectOS gives teams the review, deployment, and operational controls that keep every iteration understandable, approved, and governed.
Security and governance
Keep data in your network.
Let AI work inside permissions.
ObjectOS can deploy and operate ObjectStack apps on your infrastructure. Business records, identities, audit logs, and files stay under your control; AI agents access objects through governed tools and inherit the signed-in user’s permissions.
Explore security and governance →Data residency
Connect your databases and storage. Unless you configure an external service, ObjectOS does not send telemetry, contact a license server, or transmit data back to ObjectStack.
User-scoped AI
Agents act as signed-in users and obey object, record, and field permissions, so they cannot see data the user cannot see.
Approval and audit
Structural changes go through a human approval queue. Reads, writes, tool calls, and permission changes can be written to audit logs.
Offline ready
Run in a VPC, on local servers, or in air-gapped networks with local models, internal identity, and your own secrets management.
Application templates
Start with working templates,
not a blank canvas
Helpdesk template
An AI-first customer support template for tickets, SLA, summaries, suggested replies, and knowledge retrieval.
View template source →Contracts template
Manage the contract lifecycle with metadata extraction, approval, renewal reminders, and audit trails.
View template source →Procurement template
Run purchase requests, suppliers, POs, receiving, and three-way matching as a governed application.
View template source →How it compares
Different from
the tools you know
vs Airtable
A real database with server-side logic and runtime governance — not a spreadsheet-style workspace.
Read the comparison →vs Retool
Business logic is reviewable metadata — not JavaScript scattered across screens.
Read the comparison →vs Lovable & Bolt
Agents generate governed metadata with schema and permissions — not a one-off codebase.
Read the comparison →Latest insights
Practical thinking on AI-native software
What Tools Do Forward-Deployed Engineers Use? An Ontology-First Open Stack
Five pains define forward-deployed work: plumbing eats week one, demos die in security review, requirements outrun code, patterns never compound, and the handover poisons trust. An ontology-first open stack removes each one.
How Many Tokens Is a Business App? A Complete CRM Under 150k
A complete CRM—business logic, permissions, workflows, and UI—fits under 150k tokens of typed metadata. Business logic stays under 100k; UI adds ~50k. The bundled reference CRM is ~16k.
When an AI Agent Deletes Production Data: Runtime Guardrails Beat Prompts
The Replit database incident shows a structural lesson: an agent's blast radius must be controlled by runtime permissions, approvals, and audit logs, not only by a prompt.
Next step
Start with the business data you know best.
Connect one existing system, define its key business objects, and let your agent ship the first governed AI-written application as a small metadata diff.
Learn how to connect existing systems →