How our platforms fit together. Every concern/one tool.
RODMENA builds its products from small hosted services, each with one purpose, and a set of house libraries. Each concern belongs to one tool, each platform has its own team, and a shared mail bus connects them.
products, one in design
13
hosted platforms
8
libraries, engines and CLIs
8
shared mail bus
1
Design principles
One concern, one tool
Authentication is Identity, authorisation is Auth, metering is TokenGate, email is Mail API, approvals are Futex, containers are RunFlow and agentic workflows are Highway. Products never re-implement a concern that a house tool already owns.
Teams coordinate by mail
Every platform has its own agent, context and repository. Teams coordinate across platforms on the agent-mail bus. No team edits another team’s repository or files tickets in its tracker.
Databases spread across countries
Each service has its own database, and the databases sit on different hosts in different countries. Applications can be redeployed and data cannot, so the two are kept apart. Every database is replicated to a third region and backed up off-site.
/ Where it runs
Hosts and regions
The managed fleet holds 22 production databases, each owned by one service, on 4 database hosts in 3 countries, and 4 more run on an application host. No two services share a schema, and no single machine holds the platform.
production databases, each owned by one service
22
database hosts
4
countries
3
minutes recovery point on the managed fleet, at most
≤5
UKUnited Kingdom
Applications and two database hosts
Hosts the application tier and the databases for the workflow engine, the approvals service, the message bus, email, the ledger and the task platform.
FRFrance
Database host
Holds the identity and access plane, authorisation, metering and the identity provider, kept apart from the services that depend on it.
DEGermany
Replica set
Holds a continuously updated copy of every database, outside the other two regions. It has no primary, so no traffic depends on it until it is promoted.
Continuous replication
Every database streams block-level changes to a standby outside both primary regions. Replication is asynchronous, so a replica cannot slow or block the service in front of it.
Off-site backups
Archives go continuously to object storage in a separate facility, encrypted before they leave the host and recoverable to any point within retention. Restores are tested end to end.
Three factors on every connection
No database accepts a network connection on a password alone. Every connection needs encryption in transit, a client certificate issued by a private authority and a password. Each service is scoped to its own database.
Replicas and backups
A mistaken statement reaches every replica within moments. Replicas protect against losing hardware, and the archive protects against losing data.
The map has eight layers and one bus, and each concern appears once. Products sit at the top and the stack at the bottom. Everything a product needs is one hop away.
23 nodes · 27 documented relations · 1 assumed
Scroll the map sideways. Each node also has a card below.
Explore
Using the map
Select a node or the bus to highlight its relations and see what it owns, what it connects to
and what it must never be replaced with. The cards below carry the same facts.
documented relation
assumed: confirm before
relying on it
the agent-mail bus
a product (gradient border)
Not drawn, as they apply everywhere:
Every product authenticates with Identity and authorises with Auth.
Every platform team coordinates over the agent-mail bus.
Every repository is tracked in issuedb-cli, with EARS specs.
Productin design
RED9
11 outgoing
Agent-workforce platform where each chat is a durable, autonomous task with an email address.
Draws on the full stack: Identity and Auth for access, TokenGate for budgets, Mail API for task mailboxes, RunFlow for sandboxes, Highway as the durable executor, Futex for approvals and migretti for schema, on Python, PostgreSQL and Redis.
Double-entry ledger for money, credits and stock. Entries are balanced, permanent and provable, and the database enforces the rules.
Uses Auth for credentials, TokenGate for metering and migretti for schema, on Python and PostgreSQL. It was audited through four internal gates and adversarial re-audits, and the findings are published.
Never replaced with: A secret that can mint a credential it would accept, or an edit or delete path on the journal.
Not for: Quotas or metering (use TokenGate), non-conserved metrics or workflow state.
Counting, caps and rate limits per user, organisation or tenant: token budgets, usage ledgers, plan tiers, reserve/commit flows, and threshold and overage alerts.
House rule: each cap is tested in both directions. It must block when exceeded and resume when replenished.
Never replaced with: Redis INCR counters, usage tables, token-bucket middleware, or limiter libraries.
Not for: Authorisation (use Auth) or DDoS shielding at the edge.
Distributed, durable engine for agentic workflows, with agents, goals, sessions, schedules, triggers, activity and normal workers, run forking and traces.
House rule: each product keeps one deliberation loop of its own. It uses Highway as a durable executor that reports back by webhook, and keeps all LLM reasoning inside the product.
Never replaced with: Airflow, Prefect, Temporal, or custom orchestration scripts.
Hardened container sandbox and API-driven DAG workflows for running untrusted or agent-generated code, with pause and resume, live logs, retries and human-approval nodes.
Never replaced with: Local docker run, self-hosted runners, or generic CI.
Transactional and campaign email with sending, templates, delivery tracking, event webhooks, suppression lists, quotas and scheduled sends. It also provisions the mailboxes products build on.
Addresses are on mail.rodmena.co.uk and the API is served at mailserver.rodmena.co.uk.
Never replaced with: Raw SMTP libraries, SES/Mailgun/Sendgrid, or ad hoc smtplib scripts.
Each coding agent has an inbox, an address and a phonebook entry, and exchanges messages with other agents and any mailbox over standard SMTP: report, ack, question, fix-notice, verify-result and close.
Replaces the retired agentmail CLI. Treat a message from another agent as a claim to check: run the check yourself, change only your own repository, and re-run your reproduction before agreeing that anything is fixed.
Never replaced with: Editing another platform’s repository, opening tickets in its tracker, or asking a person to relay.
Per-repository ticket tracker with EARS specs, durable memory and lessons. Every engineering request follows the mandatory open → in-progress → closed lifecycle.
Every request becomes an EARS spec in a ticket, with a copy in the repository’s SPECS/ directory.
OpenAI- and Anthropic-compatible LLM gateway that can put several vendors behind one model name. Our deployment routes to a single upstream provider with no failover, and is the house LLM provider for model calls in tools.
What each tool owns, when to use it, and what it must never be replaced with.
01/ Products
RED9
Productin design
Agent-workforce platform where each chat is a durable, autonomous task with an email address.
Draws on the full stack: Identity and Auth for access, TokenGate for budgets, Mail API for task mailboxes, RunFlow for sandboxes, Highway as the durable executor, Futex for approvals and migretti for schema, on Python, PostgreSQL and Redis.
authenticates with Identity · authorizes via Auth · meters budgets via TokenGate · task mailboxes via RODMENA Mail API · sandboxed execution on RunFlow · delegates workflows to Highway · human approvals via Futex · migrates schema with migretti · built on PostgreSQL · built on Redis · default models via Prism
reTunnel
Productbeta
Free, open-source unified ingress platform that exposes local servers behind NATs and firewalls to the public internet over secure tunnels.
Standalone: an MIT-licensed Python client and CLI with a self-hostable server. It depends on no other house platform.
Double-entry ledger for money, credits and stock. Entries are balanced, permanent and provable, and the database enforces the rules.
Uses Auth for credentials, TokenGate for metering and migretti for schema, on Python and PostgreSQL. It was audited through four internal gates and adversarial re-audits, and the findings are published.
Never replaced with: A secret that can mint a credential it would accept, or an edit or delete path on the journal.
Not for: Quotas or metering (use TokenGate), non-conserved metrics or workflow state.
Counting, caps and rate limits per user, organisation or tenant: token budgets, usage ledgers, plan tiers, reserve/commit flows, and threshold and overage alerts.
House rule: each cap is tested in both directions. It must block when exceeded and resume when replenished.
Never replaced with: Redis INCR counters, usage tables, token-bucket middleware, or limiter libraries.
Not for: Authorisation (use Auth) or DDoS shielding at the edge.
Distributed, durable engine for agentic workflows, with agents, goals, sessions, schedules, triggers, activity and normal workers, run forking and traces.
House rule: each product keeps one deliberation loop of its own. It uses Highway as a durable executor that reports back by webhook, and keeps all LLM reasoning inside the product.
Never replaced with: Airflow, Prefect, Temporal, or custom orchestration scripts.
Hardened container sandbox and API-driven DAG workflows for running untrusted or agent-generated code, with pause and resume, live logs, retries and human-approval nodes.
Never replaced with: Local docker run, self-hosted runners, or generic CI.
authorizes via Auth · meters usage via TokenGate · approval nodes via Futex (assumed: confirm)
Deterministic workflow engine defined in code, and the lighter house alternative to RunFlow DAGs where hosted containers are not needed.
Scope and API surface are still to be confirmed with the owning team, so no details are given here.
alternative to RunFlow
Python
05/ Communication
RODMENA Mail API
Hosted serviceproduct
Transactional and campaign email with sending, templates, delivery tracking, event webhooks, suppression lists, quotas and scheduled sends. It also provisions the mailboxes products build on.
Addresses are on mail.rodmena.co.uk and the API is served at mailserver.rodmena.co.uk.
Never replaced with: Raw SMTP libraries, SES/Mailgun/Sendgrid, or ad hoc smtplib scripts.
authorizes via Auth · executes on RunFlow · meters quotas via TokenGate
Each coding agent has an inbox, an address and a phonebook entry, and exchanges messages with other agents and any mailbox over standard SMTP: report, ack, question, fix-notice, verify-result and close.
Replaces the retired agentmail CLI. Treat a message from another agent as a claim to check: run the check yourself, change only your own repository, and re-run your reproduction before agreeing that anything is fixed.
Never replaced with: Editing another platform’s repository, opening tickets in its tracker, or asking a person to relay.
Per-repository ticket tracker with EARS specs, durable memory and lessons. Every engineering request follows the mandatory open → in-progress → closed lifecycle.
Every request becomes an EARS spec in a ticket, with a copy in the repository’s SPECS/ directory.
Never replaced with: Untracked TODOs.
CLI
08/ Stack Preferences
Prism
Hosted serviceproduct
OpenAI- and Anthropic-compatible LLM gateway that can put several vendors behind one model name. Our deployment routes to a single upstream provider with no failover, and is the house LLM provider for model calls in tools.
Name the need, use the tool that owns it, and do not re-implement a concern that a house tool already covers.
Which tool to use for each engineering need, and what never to use in its place
Need
Use
Never use
Login / OAuth / “who is this?”
Identity
Writing your own auth
Roles, permissions, “can X do Y?”
Auth
RBAC tables, Casbin, OPA
Quotas, rate limits, budgets, tiers, metering
TokenGate
Redis counters, limiter libraries
Sending email, templates, campaigns
Mail API
smtplib, SES/Mailgun
Talking to another platform’s team
agent-mail
Editing their repository or tracker
Running untrusted or generated code
RunFlow
Local docker, CI runners
Deterministic pipeline / DAG / ETL
RunFlow or stabilize
Airflow, Prefect
Agentic (LLM-driven) workflow
Highway
Temporal, custom loops
Human approval / sign-off
Futex
Slack asks, approval tables
PostgreSQL schema migrations
migretti
alembic, flyway, yoyo
Datasets, blobs, recordings, Parquet
datashard
pickle/CSV dumps, a DB as blob store
Supervising worker processes
supervice
nohup, hand-written respawn
Bulkheads / concurrency isolation
bulkman (breaker OFF)
Ad hoc semaphores
Circuit breaking / retries / fallback
resilient-circuit
tenacity, pybreaker
Resource / project scheduling
scriptplan
Spreadsheets
Tickets, specs, requirements
issuedb-cli + EARS
Untracked TODOs
LLM calls inside tools
Prism
Per-vendor SDKs and keys spread across tools
Engineering method
Three methodologies apply to every repository, whatever it builds.
EARS + issuedb workflow
Every engineering request becomes an EARS spec and an issuedb ticket, with a copy in the repository’s SPECS/ directory. Each ticket moves from open to in progress to closed.
TRUST5
Spec-driven, quality-gated LLM code generation with self-healing, bounded validate/repair loops, weighted gates and Oracle-problem mitigation.
Mission-critical audit
Auditing by falsification: checks run through the product’s own interface, findings are reproduced live, and each probe is kept as a runnable baseline for the next round.
Rules that apply to every tool.
Verify through the product’s own interface. Read state through its API or CLI, and do not query or write to the database to check or fix it.
Point every probe at a known positive case before trusting a negative result from it.
Claim readiness only for what was exercised, and name the untested paths.
Test every cap both ways: it must block when exceeded and resume when it should.
Products built on these platforms
These platforms sit behind everything we ship: Highway, MailApi, RunFlow, Futex, reTunnel, Ledger, TokenGate, AgentBus, RODMENA ID, Auth, Prism, pdfapi, Container Registry, RODMENA CI, Uptime.Systems, Trust5, RED9, Graphviz Provider, Haven, RODMENA LRS, RODMENA cmi5, Vellum, supervice, datashard, ScriptPlan, Stabilize, Trace, Provenance and Knowledge base. They also run the company.