Goal
Close the gaps between Company OS and a comparable agent-orchestration product, in the one area where the comparison found real ones: runtime supervision. Company OS knows how to plan, budget, govern and staff work. It does not reliably know when a run has stopped or who owns the workspace it ran in.
What the audit found, and what it did not
Company OS is not behind on concept coverage. Audited against the source: 31 models, 60+ services, 37 API modules, 251 routes, 8 agent adapters, 31 frontend views. Org chart, budgets with per-step cost rollup, approvals and review gates, boards, sprints, backlog, goals, portability — all present. The skills subsystem is materially richer on our side: we have promotion, gap detection, dependency resolution, a manifest parser, a validator and governance; the source has a catalog and a runtime selection cache.
The gaps are narrow and they are not about features. They are about the system knowing its own state.
Tasks
Why these three
Each was demonstrated on 2026-09-16 rather than inferred from a feature comparison:
- Two coordination sessions ended mid-work. Their claims outlived them, blocking three already-merged worktrees no present session could release, and stranding two issues on a dead owner. Nothing detected it.
- The worktree ceiling then blocked the release-pipeline fix. The workaround was to abandon worktrees and commit through the GitHub API — which silently skipped every local hook, producing an unformatted file and three malformed commit subjects that CI caught.
- The GUI-coverage question could not be answered at all.
scripts/audit_api_wiring.py --dead-surface prints exactly the list of backend paths no frontend reaches, has never been run in CI, and does not contribute to any exit code.
Deliberately not adopted
- Skills catalog — ours is richer. Name absence in a grep was not treated as a gap; the behaviour check reversed the conclusion.
- Trust presets, announcements, status cards, tool gateway, chat-as-control-surface — name-level differences only. Behaviour was not compared, so they are not claimed as gaps.
agent_loop/slack_hook.py already exists and was not evaluated against the source's Discord/GitHub command surfaces.
- Agent-initiated secret requests — real but lower confidence, and the proposal pattern already exists as
finding_proposal. Filed only if the first three land and it still looks worth it.
Sequencing
#16817 first: #16818's lease release depends on a sweep existing to release it. #16816 is independent and is the cheapest of the three — it produces a number nobody has.
Implementation is deferred until the open-PR count falls below the adoption pre-flight gate; at filing time it was 24 against a gate of 5, with both self-hosted runners offline.
Method
Source cloned via scripts/research/safe_clone.py (#16488), which renamed its agent-instruction file to .untrusted — the injection vector handled by tooling rather than by care. Source anonymised throughout per the research rule. Every candidate gap was checked against AutoBot's behaviour before being called a gap; the skills case is why that step is not optional.
Goal
Close the gaps between Company OS and a comparable agent-orchestration product, in the one area where the comparison found real ones: runtime supervision. Company OS knows how to plan, budget, govern and staff work. It does not reliably know when a run has stopped or who owns the workspace it ran in.
What the audit found, and what it did not
Company OS is not behind on concept coverage. Audited against the source: 31 models, 60+ services, 37 API modules, 251 routes, 8 agent adapters, 31 frontend views. Org chart, budgets with per-step cost rollup, approvals and review gates, boards, sprints, backlog, goals, portability — all present. The skills subsystem is materially richer on our side: we have promotion, gap detection, dependency resolution, a manifest parser, a validator and governance; the source has a catalog and a runtime selection cache.
The gaps are narrow and they are not about features. They are about the system knowing its own state.
Tasks
Why these three
Each was demonstrated on 2026-09-16 rather than inferred from a feature comparison:
scripts/audit_api_wiring.py --dead-surfaceprints exactly the list of backend paths no frontend reaches, has never been run in CI, and does not contribute to any exit code.Deliberately not adopted
agent_loop/slack_hook.pyalready exists and was not evaluated against the source's Discord/GitHub command surfaces.finding_proposal. Filed only if the first three land and it still looks worth it.Sequencing
#16817 first: #16818's lease release depends on a sweep existing to release it. #16816 is independent and is the cheapest of the three — it produces a number nobody has.
Implementation is deferred until the open-PR count falls below the adoption pre-flight gate; at filing time it was 24 against a gate of 5, with both self-hosted runners offline.
Method
Source cloned via
scripts/research/safe_clone.py(#16488), which renamed its agent-instruction file to.untrusted— the injection vector handled by tooling rather than by care. Source anonymised throughout per the research rule. Every candidate gap was checked against AutoBot's behaviour before being called a gap; the skills case is why that step is not optional.