Case study 14 / 26
Sugar OS
An AI operating system in Rust — memory, knowledge graph, policy-gated skills, agents, workflows and monitoring — built from a 259-page engineering blueprint, with a phone as the command center.
- Status
- In development
- Domain
- ai · security · cloud
- Source of claims
- Private repository README and decision records (reviewed). Source is not public.
A 25-crate Rust workspace: storage and event journal, a kernel with Cedar-backed policy and an approval broker, hybrid retrieval and a knowledge graph, provider-agnostic AI routing with cost governance, a 17-agent framework, a durable workflow engine, an AI SRE monitor, a Tauri desktop app and a remote control center paired to your phone.
01/The problem
An assistant that can act on your machines and accounts needs more than a model: memory it can forget on purpose, permissions it cannot exceed, approvals you sign, workflows that survive crashes, and an audit trail you can verify.
02/The system
A 25-crate Rust workspace: storage and event journal, a kernel with Cedar-backed policy and an approval broker, hybrid retrieval and a knowledge graph, provider-agnostic AI routing with cost governance, a 17-agent framework, a durable workflow engine, an AI SRE monitor, a Tauri desktop app and a remote control center paired to your phone.
03/Scope
- 01Sessions, a capability model, Cedar-backed policy, an approval broker, a scheduler and a supervisor.
- 02Memory with capture, reconciliation, hybrid retrieval, decay and verified forgetting; local ingestion and a graph-augmented knowledge store.
- 03Provider-agnostic AI routing with hard-constraint filtering, scoring, failover, cost governance and response caching.
- 04A durable workflow engine that commits state before each side effect, resolves unknown states through an idempotency probe, and compensates with sagas.
- 05A monitoring center with HTTP probes, SLO burn rates, a ten-state incident lifecycle and gated remediation.
- 06A Tauri desktop app and a remote control center: an always-online primary, worker machines that dial out, and a phone PWA for approvals.
04/Engineering
Every action passes one chokepoint
Desktop commands and skill dispatch go through the same Cedar authorization point; community plugins are capped structurally, and skills are Ed25519-signed.
Crash safety is tested
A crash-injection suite runs in CI on Linux and Windows alongside builds and tests on all three platforms.
Honest about gaps
Every phase is audited against the blueprint's own exit criteria, and unbuilt capabilities are listed as named gaps rather than implied.
05/Interface
Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.
06/Tech stack
- Rust
- Tauri v2
- Cedar policy
- gRPC / HTTP
- tree-sitter
- Ed25519
- Windows named pipes
- GitHub Actions (Linux · macOS · Windows)
07/Result
Verified outcomes
- All 25 phases of the blueprint's roadmap addressed, with a completion audit across the build.
- CI runs lint, format, dependency-direction checks, cargo-deny, and tests on Linux, macOS and Windows.
Known limitations
- A third-party security audit, disaster-recovery drills and a public 1.0 release remain open.
08/Links
Private commercial codebase — no public links.
Next case study
TesseraDB →