Money HunterQualify · Produce · Verify

Architecture · public facts

Grants, not keys.

Docker jails a process. It does not decide who may act. Money Hunter is a line with a gate in front of it: named grants, a qualify step, a producer, a verifier. The public site shows that line. The desk that starts workers is not on this internet.

Public storefront and the qualify-produce-verify line. Operator desk drawn as off-site.
Storefront is public. The line is explained here. The operator desk is not published.

Thought

Qualify is a gate

Accept public-data jobs: CSV, public pages, public PDFs, structured research. Reject harvest, login walls, physical gigs, owner-identity tasks. A gate, not a vibe. Rank is not a grant.

Development

Produce inside the grant

The producer only gets public-read. It writes a review or a table. It does not receive every key on the host. Spend, marketplace, and account-creation stay owner-gated.

Design

Verify before it leaves

A second role checks the artifact: public-read only, evidence attached, no credentials used. If fulfillment could mark itself paid, it would. Money stays in the operator books, not on this site.

Why the desk is not here

A dashboard bound to the public internet becomes the product, and then it becomes the attack surface. This hostname is the catalog and the explanation. Tokens, logs, worker start/stop, and queue telemetry stay on the LAN.

Company OS

Company OS is the reusable authority layer — isolation, ALLOW / HOLD / DENY, receipts, restore. It still does that job. Packet Press is a different company on that engine. Money Hunter is the original laboratory and is not a Company OS tenant, so an OS restore cannot overwrite this line. That is an engineering fact, not the pitch. The pitch is the file you keep.

companyos.thecriners.com · GitHub · discovery 0.5.0-rc1 · Security Model 1.2.0