Twenty-six autonomous agents. A 90-day takeover protocol. A self-evolving intelligence layer that compounds your brand's advantage — engineered to replace any agency retainer entirely. Audited 8 times. Spec score: 9.3/10. 124 tables live in production.
WebRenders OS isn't a campaign tool. It's an operating system that fuses an elite creative engine, real-life business scenarios, a client self-serve web UI, and a global expansion architecture into one self-evolving layer. Six capability clusters orbit a single intelligence core — every cluster feeds the others.
The vision beats Tempo, AdCreative.ai, Pencil, Photoroom, and Vidmob360 combined — not by being bigger, but by being one system where creative intelligence, marketplace intelligence, and operational discipline share the same data spine.
Brand DNA vectors, golden references, hedged generation, VLM critic jury, LoRA library. Creative treated as engineering, not art — every output scored, embedded, and learned from.
Ad fatigue auto-refresh, WhatsApp catalog, review-to-testimonial pipeline, clone-this-video, product launch assistant. Not features — pre-built solutions for real D2C pain.
Thin Next.js + shadcn canvas. Generate, variants grid, library, brand kit. Every action flows through the same visualRouter + ledger the agents use. White-label ready.
Region, locale, vertical, currency schema. Phase 1 SEED shipped in v7.9.35. 16 channel adapters and 9 vertical plugins queued for the future. One spine, every market.
Hypotheses are Brier-scored. Patterns are extracted. Strategy is logged. Tomorrow's brief is informed by yesterday's outcome. The system compounds advantage every cycle.
Phase-gated actions, per-agent kill switches, tripwire freezes, regret-budget circuit breakers, tamper-evident audit logs. Engineering rigor applied to marketing operations.
For most D2C brands, the agency fee nearly equals the ad spend itself — while the underlying campaign data is broken, the algorithm flies blind 22% of days, and creative testing is non-existent. The result is a brand that's bleeding month-over-month while paying a premium for the privilege.
The agency fee is structured as a fixed retainer regardless of performance. It scales with your spend, not your outcomes — meaning the worse your ads perform, the more you pay the agency in effective terms. Eliminating it is the single largest profitability lever, instantly converting a loss-making brand into a profitable one.
A misconfigured Conversions API means Meta's algorithm only sees 30–50% of your actual purchases. The Event Match Quality sits at 3–5 out of 10. Roughly 22% of trading days show zero revenue simply because the data never made it back to the ad platform. Every pattern, every hypothesis, every ROAS comparison runs on corrupted data until CAPI is fixed.
Modern performance marketing is creative-as-targeting — each hook variant is a different audience signal. Most brands run fewer than three creatives per ad set, never retire fatigued ones, and have no systematic testing pipeline. The category average is 2.8–4.5× ROAS; the headroom is enormous when creative is treated as engineering, not art.
WebRenders OS replaces the agency with a solo operator and an intelligent automation stack that observes, learns, recommends, and acts — under strict human approval. Over 90 days it shadows your current setup, parallel-runs its own campaigns, then takes over completely with proven, data-backed results.
WebRenders OS treats marketing the way software treats infrastructure. Twenty-five specialized agents run on a hardened Postgres spine, each with cached system prompts, phase-gated permissions, per-agent kill switches, and an approval workflow with veto power. Every action writes to a tamper-evident, hash-chained audit log. Every recommendation references data from tables that compound in value with every cycle.
The system gets smarter about your specific brand's audience with every cycle. Hypotheses are scored. Patterns are extracted. Strategy is logged. Tomorrow's brief is always informed by yesterday's outcome — and the day's LLM cost stays under $0.75.
Approve, reject, or discuss every recommendation in-line from a 3-person ops group. No new dashboard to learn. Free, unlimited, with role-checked slash commands.
Hypotheses → patterns → strategy_log. Every rejected recommendation still teaches the system. Calibration scores per agent, per category, per cycle.
The infrastructure + LLM envelope is a hard gate. Prompt caching + a custom 50-line tool loop keep actual spend at ~Capped.
117 RLS-protected tables. Per-org schemas, per-org MCP configs, per-org budget envelopes. Add the next brand without re-architecting anything.
Daily metrics flow in from 13+ MCP channels. CAPI Worker ensures the data is clean — no more 22% blind days.
Agents draft hypotheses with explicit counterfactuals — "if we cut budget on X, ROAS shifts by Y." Even rejected actions become learning.
Every hypothesis is Brier-scored against the actual outcome. Calibration tracked per agent, per category, per cycle.
Scored hypotheses roll up into patterns. Patterns embed into the strategy_log. Tomorrow's brief is conditioned on yesterday's outcome.
This is the moat. The agency starts fresh every Monday. WebRenders OS starts every Monday with 7 more days of brand-specific learning — and that compounding gap is impossible to close without your data.
Every brand today picks from the same four options: hire an agency, build an in-house team, stitch together point tools, or do nothing. Each one fails for a different reason — and WebRenders OS was built specifically to close every one of those gaps. Here's the honest side-by-side.
Spend-scaled retainer
A team of account managers, media buyers, and creatives. Charges a fixed retainer that scales with your spend, not your outcomes. Holds your data hostage. Hands rotate every 6 months.
Full team payroll
A performance marketer, a creative, a data analyst, a marketplace specialist. High context, high cost, high attrition risk. When one person leaves, six months of brand knowledge walks out the door.
AdCreative · Pencil · Photoroom · Tempo
A dashboard for creative, a script for CAPI, a freelancer for ads, a Slack channel for ops. Each tool owns a slice of your data. No shared spine, no learning loop, no accountability when something breaks.
Flat infrastructure
One operating system. 26 agents, 13+ MCP channels, an elite creative engine, a self-evolving intelligence layer, and a 90-day takeover protocol — all on a Postgres spine you own, encrypted with your keys.
| Capability | Agency | In-house | Stitched tools | WebRenders OS |
|---|---|---|---|---|
| Monthly cost (real) | High | Highest | Per-seat SaaS | Flat |
| Pricing model | Spend-scaled retainer | Fixed payroll | Per-seat SaaS | Outcomes-priced · flat cap |
| Data ownership | ||||
| Brand-specific learning loop | ||||
| Compounding intelligence (Brier-scored) | ||||
| Approval workflow with veto | Email/Slack | |||
| Tamper-evident audit log | ||||
| Multi-tenant + 1-click install (RLS) | ||||
| DPDPA-compliant erasure | ||||
| Elite creative engine (V0–V4) | ||||
| CAPI Worker at the edge | ||||
| Marketplace track (Amazon · Flipkart · Myntra) | ||||
| GEO + AEO citation layer | ||||
| Bus factor | Account manager | 1 person | The integrator | The system + 1 operator |
| Onboarding time | 2–4 weeks | 3–6 months (hiring) | 2–8 weeks (stitching) | 90 days to full takeover |
Agencies charge a fixed retainer regardless of performance — meaning the worse your ads perform, the more you effectively pay them. The retainer scales with your spend, not your outcomes, creating a perverse incentive: they profit from your ad budget whether it works or not.
WebRenders OS charges for actual LLM tokens consumed — capped at Flatnth hard. When the system recommends nothing, it costs nothing. When it recommends aggressively, you approve every rupee in advance. The economic alignment is structural, not contractual.
And the agency's intelligence walks out the door every time an account manager quits. WebRenders compounds it into your Postgres — every cycle, every pattern, every hypothesis score stays in your database forever.
A full in-house team — performance marketer, creative, data analyst, marketplace specialist — costs Payrollnth in payroll alone, before benefits, tools, and office. Hiring each role takes 3–6 months. The bus factor is one person per function; when they leave, six months of brand knowledge walks out the door with them.
WebRenders OS replaces that entire team for Flatnth, ships in 90 days, and never takes a sick day. The 26 agents cover every function an in-house team would — strategy, creative, marketplace, retention, margin, CRO, infra — and the operator just approves.
When the operator goes on vacation, the system keeps running daily briefs, monitoring tripwires, and queuing approvals. The bus factor becomes the system itself, not any single human.
AdCreative.ai generates images. Pencil writes copy. Photoroom removes backgrounds. Tempo schedules. Each is a point tool that owns a slice of your data — and none of them share a spine. There's no shared pattern library, no cross-tool learning loop, no approval workflow that ties creative generation to ad performance to margin impact.
WebRenders OS is one operating system where the creative engine, the marketplace track, the CAPI worker, the 26 agents, and the audit log all read from and write to the same Postgres spine. The visual-director agent knows which creatives the creative-fatigue agent flagged. The margin-auditor knows which orders the cart-recovery agent is targeting.
And every tool above is a dashboard — it shows you what happened. WebRenders OS decides what to do next, drafts the action, and executes it under your approval. That's a category difference, not a feature gap.
Generates ad creatives from templates. No marketplace track, no CAPI, no approval workflow, no compounding intelligence. WebRenders treats creative as one of 26 agent functions on a shared spine.
AI-assisted creative for ads. No operations layer, no audit trail, no multi-tenant security, no marketplace integration. WebRenders replaces the entire agency, not just the copywriter.
Best-in-class background removal and image editing. One stage of a 7-stage visual pipeline. WebRenders wraps rembg + Bria + generation + critique + lineage into one closed loop.
Human creative marketplace at scale. No autonomous agents, no brand DNA, no learning loop, no takeover protocol. WebRenders is the operating system; Vidmob is a supplier.
Schedules and manages Meta ad campaigns. No creative engine, no marketplace, no security layer, no self-evolution. WebRenders schedules ads as one action among hundreds.
Best-in-class D2C analytics. Shows what happened. WebRenders decides what to do next — and does it, under approval. Dashboards observe; operating systems act.
The category difference. Every named competitor above is a point tool or a marketplace. WebRenders OS is the operating system that connects creative generation, marketplace intelligence, ad operations, security, and self-evolution into one closed loop on a single data spine — and replaces the agency retainer entirely.
The protocol is non-negotiable. Nine Day-0 audit gates prove access and baseline every metric. Fifteen days of pure observation. Forty-five days of parallel campaigns. Then full takeover — with proven, data-backed performance the agency cannot dispute.
The system observes the current agency's setup without touching anything. Every metric, every creative, every campaign is logged. The CAPI Worker is deployed first — fixing the 22% zero-revenue-day problem is a prerequisite for clean data, not a feature. Tripwires activate. Baseline is locked.
The system begins surfacing critical fixes via Telegram. Creative fatigue triggers fire. Margin alerts on negative-CM3 orders. Cart recovery flows drafted. The agency still runs the ad account — but every recommendation from WebRenders is now data-backed and timestamped, creating an objective record.
WebRenders runs its own campaigns alongside the agency. Every campaign, budget shift, and creative is a draft awaiting Telegram approval. The operator compares apples-to-apples: same spend window, same product mix, different intelligence layer. By Day 60, the result gap is usually obvious.
The agency is fired. WebRenders OS now publishes, pauses, and shifts budget autonomously — under approval for high-risk actions. The retainer monthly fee drops to ~15–25K (operator retainer + LLM cost of Capped + creative). The brand moves from loss to profit on Day 90.
The 90-day protocol is documented down to the day in the spec. Day 0 has 9 audit gates. Day 75 has a second restore drill. Every phase transition requires explicit operator confirmation. This is engineering discipline applied to marketing operations.
The Vision Blueprint is the north star; this 5-phase corrected roadmap is the execution plan. Phase 0 fixes 40 open P0s the blueprint missed. Phase 1 ships global expansion scaffolding. Phase 2 builds the elite engine core. Phases 3–5 expand scenario coverage, the client web UI, and global rollout — each gated on a real-world condition, not a calendar.
Non-negotiable. The Vision Blueprint completely missed this. toolLoop wiring, 16 wireWorkers, migrations 001-008, DPDPA erasure reach, 9 ADVISORY gates → ENFORCES.
v7.9.35 schema additions (shipped) + config YAMLs + interface implementations + next-intl migration. Zero behavior change to existing India operations.
5 tables (brand_dna_vectors, creative_briefs, creative_critiques, creative_performance, golden_references) + 3 agents + 4 MCP tools + hedged generation + VLM jury + lineage DAG.
Ad fatigue auto-refresh. WhatsApp catalog. Review-to-testimonial pipeline. The highest-ROI real-life scenarios wired end-to-end, approval-gated where irreversible.
Remaining 10 elite tables + 7 agents + pipeline stages 2/4/5/6/7 + LoRA library + Client Web UI MVP. GATED on SaaS pivot + G5 + first paying client.
Tier 2/3 scenarios + clone-this-video + 16 channel adapters + 9 vertical plugins + schema split. Continuous evolution driven by real client demand, not roadmap theatre.
Each agent is a cached system prompt with tools, a phase gate, a per-agent kill switch, and a tripwire freeze check. They run on a 50-line custom tool loop — no Agent SDK, no 30s timeouts, full control over budget, retries, and iteration limits. Every call routes through Bifrost. Every token is logged.
strategist-multi-lens
Synthesizes trend signals, metrics, and pattern library into strategic recommendations. Recommends — never executes without approval.
creative-director
Generates 3–5 hook variants per trend signal. Enforces creative-as-targeting. Never drops below the diversity minimum per ad set.
amazon-specialist
ACoS targeting (30% blended, 35% conquest). ASIN conquest only where rating or price wins. SP-API halt switch on rate-limit.
shopfront-optimizer
Shopify CRO. Product schema cleanliness. Theme snippet CAPI partner integration. Cart abandonment reducers.
listings-optimizer
A+ Content. Title and bullet optimization. Brand Registry compliance. Cross-marketplace listing sync.
retention-strategist
Cohort analysis, LTV modeling, win-back flows. WhatsApp catalog (Phase 2+). Review-to-testimonial pipeline.
margin-auditor
Flags negative-CM3 orders. Surfaces the top 3 margin-destroying SKUs via /margin command. Per-product profitability.
trend-scout
Scans 13+ intelligence channels: Google Trends, Reddit, Instagram, competitor sites, Amazon, news, weather, YouTube. IPI-wrapped.
creative-fatigue
Monitors frequency, CTR decay, and age per creative. Auto-triggers refresh recommendations. Never drops below 3 active per ad set.
conversational-ask
Natural-language queries against the brand's own data. "How did the Aqva Leo cleanser perform last week?" → grounded answer with sources.
whatif-counterfactual
"What if we cut the beard line by 30%?" — modeled impact on margin, ROAS, and inventory without spending budget to find out.
cart-recovery
Identifies recoverable abandoned carts. Drafts WhatsApp/email flows. Approval-gated per recipient to honor DPDPA consent.
daily-brief
Morning Telegram digest: yesterday's spend, ROAS, ACoS, EMQ, top creatives, alerts, and the top 3 things to act on today.
pre-mortem
Before any high-risk action: imagines the failure mode, enumerates causes, recommends mitigations. Reduces regret-class mistakes.
funnel-auditor
Step-by-step funnel drop-off analysis. Identifies which stage leaks most. Recommends CRO fixes for approval.
friction-auditor
UX friction detection across checkout, search, PDP. Surfaces the highest-impact, lowest-effort fixes.
script-writer
Generates reusable ops scripts (Shopify flows, SP-API queries, webhook handlers). Code goes through review before deploy.
platform-reconciler
Cross-checks Shopify orders vs Meta purchase events vs Amazon settlement reports. Flags attribution drift.
version-watch
Pinned model versions, extension versions, and package versions. Quarterly sweep with arena leaderboard check. Never auto-swaps.
geo-monitor
llms.txt, schema.org, brand-facts.json. Tracks AI engine citations of your brand. DPDPA-compliant AI crawler robots.txt.
action-executor
The single throat every approved write-action flows through. Idempotent run_key, dry-run mode, rollback handle per platform.
capability-manager
Maintains the registry of what the system can actually do. Verifies new MCPs, agents, and tools are wired end-to-end before going live.
visual-director
Compiles one brief into model-specific prompt packs (Seedream, FLUX.2, Nano Banana Pro, Veo/Kling). Few-shots from top-scored packs.
visual-producer
Routes jobs through visualRouter. Variant fan-out, critic selection, draft→finish ladder. License-aware routing for client deliverables.
cro-auditor
Independent review of every published change. Did the predicted lift materialize? Did the regression we feared appear? Closes the loop.
self-marketing-strategist
The system markets itself. Designs creative briefs for WebRenders OS's own Meta/LinkedIn ads, tracks CAC per channel, manages lead nurture. The recursive proof: "This ad was generated by the system you're considering buying."
The Agent SDK had a 30-second timeout that broke long-running tool calls. The custom tool loop gives full control over budget, retries, iteration limits, and circuit breaking — and ships in under 100 lines of TypeScript. Every agent call routes through Bifrost (semantic cache + prompt caching + fallback chain). Every token usage object is logged to token_usage.
wireWorker('strategist', async (ctx, db, data) => { if (await checkAgentHalt(ctx.org.id, 'strategist')) return; if (await checkTripwireFreeze(ctx.org.id, 'strategy')) return; await enforcePhaseGate(ctx.org.id, 'recommend'); // cached system prompt + tools + tool-loop const result = await callLLM({ agent: 'strategist', orgContext: ctx.org, tools: toolsFor('strategist'), budget: 0.50, }); await createApproval(ctx, result.recommendation); });
One Contabo VPS. Postgres 18.4 with pgvector, pgvectorscale, and pg_duckdb. Hono + TypeScript on Node 24. Bifrost as the LLM gateway. Cloudflare Workers for the CAPI edge. Telegram as the ops surface. Zero open ports — everything tunnels through Cloudflare + Tailscale.
Postgres + Hono + pg-boss + TEI containers all on one box. Backups to R2 with Object Lock. Cloudflare Tunnel + Tailscale — no SSH exposure.
The Conversions API worker runs at the edge. Multi-tenant via X-Org-Slug header. Fixes the 22% zero-revenue-day problem at the source.
Routing, fallback chain, semantic cache, prompt caching. Opus 4.8 in premium tier; Haiku 4.5 for daily agents. ~12% quality-per-dollar lever via Advisor tool.
pgvector 0.8.4 + pgvectorscale 0.9.0 + pg_duckdb for OLAP. UUIDv7 PKs for time-sortable B-tree inserts. HNSW indexes for similarity.
Multi-tenant from Day 1 means the same system that runs one brand runs fifty. Per-org schemas, per-org MCP configs, per-org budget envelopes, per-org Telegram groups. The infrastructure cost stays flat; the operator's revenue per brand compounds.
Flat infrastructure. Proves the system on one brand (Mufasa) before scaling. The 90-day takeover protocol runs end-to-end. All 26 agents, full schema, full security — same code.
Triggered at Day 120. Per-org Telegram groups, per-org budget envelopes, per-org MCP configs. Marginal infrastructure cost approaches zero — the VPS, Postgres, and Bifrost are already paid for.
Pattern library now compounds across brands. Cross-brand benchmarks emerge. One operator can manage 20 brands because the system does the heavy lifting — the operator just approves.
Gated on first paying client + G5 (lawyer/CA engaged). White-label Web UI ships. Per-client envelopes, per-client brand kits, per-client LoRAs. The schema was multi-tenant from Day 1 — no re-architecture.
Daily copy-on-write branch on Neon free tier. Was 2–4 hours on VPS-only. Promoted to S1 — execute immediately after schema migration.
Inspired by Foreplay — but single-operator, not multi-user SaaS. The system learns the operator's aesthetic taste. It decomposes every ad with a VLM. It predicts fatigue before launch. It curates 5 ads/day × 90 days = 450 references. No competitor has positive and negative examples. No competitor personalizes to one operator. This is the single highest-leverage build in the spec.
Operator-curated swipe file. VLM decomposes every ad: hook type, color palette, talent, lighting, emotion arc, pacing, CTA placement. HNSW index for "find 3 ads with similar hook."
Adversarial negative examples — ads to AVOID. The inverse of golden references. Every competitor only has positive examples. The VLM jury scores generated creative against BOTH.
The system learns YOUR aesthetic taste. Trend-scout pre-filters by cosine similarity > 0.7 to your last 30 swipes. By Day 90, surfaces ads you'll love 80% of the time. Unbeatable: SaaS can't personalize per operator.
Predictive fatigue — predict BEFORE launch, not after. Uses historical curves from similar creatives. Brier-scored. "Predicted fatigue: 7 days. Recommend: generate 2 replacements before Day 5."
5 ads/day surfaced by trend-scout. Inline cards: Star (golden) / Save / Skip. ~60 seconds/day. 450 curated references in 90 days.
ASCII sparkline (CTR 7d: ▁▂▄▆▅▃▂). No matplotlib, no R2, no link — 95% of PNG value at 1% of cost. Telegram-native.
Review saved swipe + bridge for Chrome extension (Phase 3). CAPI handler mirrors /leads handler.
Why this is unbeatable. Foreplay is multi-user SaaS — it can't personalize per operator. AdCreative.ai generates from templates — it doesn't learn your taste. WebRenders OS is the only system with agent-curated + human-filtered + VLM-decomposed + cross-vertical + Brier-scored pattern_library. Every new client makes the library richer for ALL clients.
The schema no longer assumes D2C. A VerticalPlugin interface lets real estate, B2B SaaS, and services clients plug in their own catalog and order tables — agents work unchanged. A single SQL command onboards a new client. Cross-org pattern transfer means every new client makes the system smarter for all existing clients. And a 1-click install script means deployment is one curl away.
Each vertical implements: catalogTable, orderTable, creativeTemplates, complianceRules, seedData, channelAdapters. Core agents read from the plugin — they don't hardcode 'products' or 'orders'.
One command generates ALL seeds for a new org: organizations row, role_org_map access, admin user, 26 agent_halt flags, 2 default constraints, brand_dna stub. Was 4–6 hours of manual SQL; now ~30 minutes.
3 new columns on pattern_library: transferable, vertical_origin, vertical_applicability. When a new client onboards, transferable patterns get COPIED to the new org. The script-writer agent queries BOTH org-specific AND transferable patterns. This is the multi-tenant moat — each new client makes the pattern_library richer for ALL clients.
curl | bash → clone → bootstrap → .env → compose up → migrate → verify. 7-step automated install. Self-hosted, AGPLv3, no vendor lock-in.
Foundation phase done. EMQ 9.3/10. CAPI Worker deployed + verified. Backup system verified end-to-end. S2 (agent application) is next.
Most "AI creative" tools start at the API. WebRenders starts at the prompt — turning the system into a prompt engine before any generation spend. By the time APIs are wired in V1, the system already knows which prompt structures win for your brand. Then V2 brings a thin web canvas, V3 closes the loop with autonomy, and V4 ships per-brand LoRAs.
System writes elite prompts. Operator pastes into consumer UIs. Scores results back. 0 API cost — seeds the learning loop before any spend.
/generate from Telegram → API generates → N variants back → critic scores → approve / re-roll / tweak. Hero jobs are T2 — explicit approval before spend.
Four-screen Next.js UI: Generate · Variants Grid · Library · Brand Kit. Every action flows through the same visualRouter + ledger the agents use.
Agents auto-brief from pattern library. Generate → score → embed → learn. Bulk jobs autonomous under daily envelope; hero jobs always approval-gated.
Per-brand LoRAs via hosted trainers (fal / Replicate). No GPU ever owned — ~1–3h rented compute per training run. White-label UI for clients.
The same creative brief is compiled into model-specific prompt packs. Each model has a different prompting grammar — and the system knows which one wins for which kind of job.
Variant fan-out + critic selection + draft→finish ladder are defaults, not options. The system explores composition on cheap routes, then re-runs the winning prompt on premium.
draft_then_finish: true variants_per_job: 4 critic: vlm-jury license_aware_routing: true hero_jobs: T2 # explicit approval
License-aware routing baked in. Client-deliverable jobs route through clean-rights models unless explicitly overridden — protecting your brand from "we used an unlicensed model" surprises.
Row-Level Security from Day 1. AES-256-GCM for every secret. A hash-chained, Merkle-rooted audit log. DPDPA erase_org wired through every PII write path. The same controls that protect one tenant protect the next — adding a brand never re-architects security.
Row-Level Security is enforced on every tenant table. Policies carry WITH CHECK clauses on writes — multi-tenant write-leak closed at the database layer. No app code can bypass it.
Every platform token, API key, and credential is encrypted at rest with AES-256-GCM. SOPS + age for the bootstrap secrets. 1Password × 2 for operator Shamir-style split.
Every action writes to action_log with prev_hash + row_hash. UPDATE and DELETE are revoked from the app role. Merkle root anchored — a superuser cannot rewrite history silently.
The /offboard Telegram command wires the erase_org producer through every PII write path. Consent withdrawal is enforced at the DB trigger level — no app-side cooperation required.
Every scraped string passes through NFKC normalization + wrapper markers before reaching an LLM. Embedded instruction attacks are neutralized at the data ingestion layer, not the prompt layer.
Cloudflare Tunnel for inbound. Tailscale for admin. No public SSH, no exposed Postgres, no webhook ports to scan. The attack surface is the size of a single Cloudflare Worker URL.
Every write action — pause, publish, budget shift, creative launch — flows through this swimlane. Low-risk actions auto-approve after 1 hour (operator can still veto retroactively). High-risk actions need explicit Telegram approval before the action-executor runs. The action_log row carries prev_hash and row_hash — and the app role has UPDATE and DELETE revoked, so history is append-only by construction. And every approved action is reversible — the /undo command flows through the reactive-router's manual_undo branch → action-executor → platform reversal, end-to-end (fixed in v7.9.35 — was silently dead for 3 releases).
Honesty is a feature. The spec explicitly labels deferred items with their trigger condition and the reason for deferral. No safety system is claimed active without a verified consuming call site. The CI gate verify-rls-attacks-execute.ts enforces this mechanically.
SEO is not dying — it's converging with GEO (Generative Engine Optimization). AI engines retrieve via live web search and RAG, so a technically sound site is still the foundation. GEO determines whether your content gets cited once retrieved. WebRenders OS ships the citation layer out of the box.
llms.txt (concise ~8KB) + llms-full.txt (full catalog + FAQs + brand story) at the site root. Generated weekly from your brand_dna and products tables. Deployed to Shopify theme automatically.
Explicitly allow GPTBot, PerplexityBot, ClaudeBot, Google-Extended. Bytespider is blocked (DPDPA transborder risk). Generated per-brand and pushed to Shopify theme.
Four schema types: Product on every PDP, FAQPage (linked to 30–40% citation lift per Princeton GEO research), Organization on homepage, BreadcrumbList on category pages.
The geo-monitor agent tracks when your brand is cited in AI engine responses — ChatGPT, Perplexity, Claude, Gemini. Weekly Telegram digest shows citation velocity and the source pages driving it.
{
"name": "Mufasa Man",
"category": "men's grooming",
"region": "IN",
"hero_products": ["Alpha Perfume", "Beard Growth Oil", "Aqva Leo Cleanser"],
"price_range": { "min": 559, "max": 2205, "currency": "INR" },
"differentiators": ["oud-based fragrances", "70% product margin"],
"fulfillment": "shopify + FBA",
"social": { "instagram": "@mufasaman", "amazon_storefront": "mufasa-in" }
}
Refreshed weekly. Served at /.well-known/brand-facts.json. This is the file AI engines actually retrieve when reasoning about your brand — and most brands don't have one.
The economics are not theoretical. They are calibrated against a real D2C brand paying a real agency a real agency retainer — and the same levers apply to almost every brand in the same situation.
WebRenders OS is one cohesive system, not a portfolio of separately-priced modules. The 31 spec files describe what's built, what's deferred, and why — every claim verified by 47 CI scripts that check the codebase mechanically.
Core, specialty, profit, infra, visual, control. Each cached, phase-gated, kill-switchable.
Multi-tenant schema from Day 1. UUIDv7 PKs. pgvector + pgvectorscale + pg_duckdb.
Official OAuth-native MCPs: Meta, Amazon, Google, Shopify, Flipkart, Reddit, YouTube, Trends.
Inline approve/reject/discuss. 13 slash commands. 3-person group with veto power.
Cloudflare edge. Multi-tenant via X-Org-Slug. Fixes the 22% zero-revenue-day problem.
4 deployment phases. Read → log → alert → suggest → draft → publish. Every write phase-checked.
Every write creates an approval_workflows entry. Auto-approve 1hr for low-risk. Veto for high-risk.
Hash-chained action_log. UPDATE/DELETE revoked. Merkle root anchored. R2 Object Lock spec'd.
/offboard command. erase_org producer wired through every PII write path. DB trigger enforced.
V0 Prompt Studio ships at 0. V1-V4 staged. License-aware routing. VLM critic jury.
llms.txt, schema.org, brand-facts.json, AI-crawler robots.txt. Citation tracking agent.
Hypotheses → patterns → strategy_log. Brier-scored. Calibration per agent, per category, per cycle.
Routing + semantic cache + prompt caching + fallback. Haiku 4.5, Sonnet 4.6, Opus 4.8.
3 containers: MuRIL (Indian langs), BGE-M3 (multilingual), Jina CLIP v2 (multimodal). 0/mo.
Mechanical checks: RLS attacks execute, claims wired, no phantom refs, file count consistent.
~1.8MB of capability files. 360° audited. Every fix co-located inline. Every deferred item honestly labeled. Score: 9.3/10 spec + 8.5/10 PII posture.
9 audit gates. Day-by-day calendar. Day 75 second restore drill. Phase transitions gated.
Region/locale/vertical/currency schema. v7.9.35 ships Phase 1 SEED — zero behavior change.
If you run a D2C brand, a Shopify store, an Amazon-led marketplace business, or any operation that pays an external agency a retainer larger than your LLM envelope would be — this is your replacement strategy.
Paying 50K–2L/month to an agency for Meta, Amazon, and Shopify management. Tired of paying a retainer that scales with spend, not outcomes. Want their brand back — with a defensible, data-backed operations layer they own.
Running 1–10 SKUs and want creative testing, CAPI, schema cleanliness, cart recovery, and a daily brief — without hiring a 5-person team. WebRenders runs the same playbook for the same flat infrastructure cost regardless of SKU count.
Amazon SC, Flipkart Seller, Myntra. SP-API integration with halt switch on rate-limit. ACoS targeting with ASIN conquest. Listing optimization and A+ Content under one roof with cross-platform reconciliation.
One operator can serve 2–5 brands with the same system. Multi-tenant from Day 1. Per-org budget envelopes. Per-org MCP configs. Per-org Telegram groups. Scale your retainer without scaling your headcount.
The pattern library, the hypothesis scores, the brand DNA — all live in your Postgres, on your VPS, encrypted with your keys. No vendor lock-in. No "we'll export your data" promise. The asset compounds in value, and it's yours.
The agency model charges for spend. WebRenders charges for actual LLM tokens consumed — capped at Flatnth hard. When the system recommends nothing, it costs nothing. When it recommends aggressively, you approve every rupee in advance.
Every cycle, the system gets smarter about your specific audience. Hypotheses are scored. Patterns are extracted. Strategy is logged. Tomorrow's brief is informed by yesterday's outcome — and the agency can never catch up because they don't have your data.
WebRenders OS treats itself as a client. A webrenders-os org lives in the multi-tenant schema. The 26th agent — self-marketing-strategist — designs creative briefs for WebRenders OS's own Meta and LinkedIn ads. The creative-fatigue agent detects when self-ads are tiring. The margin-auditor tracks CAC per channel. A daily nurture cron sends WhatsApp messages to leads who haven't responded.
The recursive proof is the whole pitch: "This ad was generated by the system you're considering buying." If the ad gets a D2C founder's attention, the system works. If it doesn't, the system knows first — and iterates.
"We audited our system 8 times. Our competitors haven't audited once. This ad was generated by the same AI that will run your marketing. Mufasa Man's ROAS went from 1.31× to 1.7× in 90 days — not 'increase your ROAS,' but a specific, verifiable number."
— Self-Marketing Strategist creative principles (v7.9.35)
The 90-day takeover protocol starts with a Day-0 audit. Nine gates, four hours, one Telegram group, and an honest assessment of what your current setup is actually doing. No deck. No sales call. Just the spec, the code, and the numbers.
Self-host or fork. No vendor lock-in.
Infrastructure + LLM. Visual envelope separate.
Or walk away with the audit. No commitment.