fabius · the operating brain above every model

one agent. above every model.

fabius is the agent; the model is the engine. Claude, GPT, Gemini, Mistral, DeepSeek, Llama, Qwen, Kimi, Grok, and more can follow the same instructions, skills, memory, safety, and verification loop — through a direct provider, a model router, or a local Ollama runtime.

fabius control plane 8 runtime paths · one brain active
autonomous agent · operating brain fabius instruction · routing · skills · memory · verification operating contractactive
every selected model receives one operating contract
  • scope
  • route
  • specialize
  • guard
  • verify
  • remember
AnthropicClaude OpenAIGPT GoogleGemini MistralMistral GroqGPT-OSS Hugging FaceOpen models OpenRouterModel router Local runtimeOllama

fabius instructs the selected model executes fabius verifies

1 agent brain 8 runtime paths 15 coordinated skills 75 no-token checks Local + console Private · sealed

Watch · the 25-second explainer

See the brain take control.

Watch one task become a fabius operating contract, move through the selected model, and return through verification and memory — end to end.

01The architecture

The model is the engine.
fabius is the brain.

fabius sits above the model. It does not replace or retrain Claude, GPT, Gemini, Mistral, DeepSeek, Llama, Qwen, Kimi, Grok, or any other selected model. It gives that model the operating instructions: what to investigate, which skill owns the work, when to act, how to verify, and what to remember.

  1. 01
    You give fabius the task.One accountable entry point for the whole job.
  2. 02
    fabius supplies the operating brain.Scope, routing, skills, safety, memory, and proof.
  3. 03
    The model follows the contract.The engine can change; the brain and standards stay.

Scout wide in what you investigate. Strike narrow in what you ship. The selected model supplies capability; fabius supplies the discipline.

02The loop

One operating loop. Any model underneath.

You choose the engine; fabius supplies the behaviour. Every model receives the same five-beat loop — investigate broadly, plan deliberately, ship narrowly, prove the result, and keep what was learned.

  1. Scout

    Fan out to understand and verify. Cheap to look, expensive to be wrong.

  2. Plan

    Weigh the load. Pick the layers, the machinery, and the cheapest model tier that holds.

  3. Strike

    Ship the single smallest correct thing. Say it in the fewest words. Nothing speculative.

  4. Prove

    Run it. Show the evidence — a test, a screenshot, a check. Never “should work.”

  5. Record

    File what was learned into memory, so the next run starts ahead — not from zero.

03The system

The brain stays. The model can change.

fabius owns the operating contract: one router, an always-on lean core, thirteen specialist layers, shared memory, and verification. Eight runtime paths connect it to direct providers, model routers, and local Ollama models. Swap the engine — DeepSeek, Claude, GPT, Llama, Qwen, Kimi, Grok, or another compatible model — and the instructions and standards stay.

The reasoning loop — every stage owned by a rule.

The same run, seen by its rules: the stages the router moves through, each answering to one researched rule — so the behaviour is a documented decision, not a mood.

  1. R1classify
  2. R4scout
  3. R2ladder
  4. R3·M1value-gate
  5. R6plan
  6. R5act
  7. R7·M2search
  8. R8refine
  9. M5·M6learn
  10. R9·M7memory

The research behind the rules.

Each routing rule comes out of fabius’s own research — derived, pressure-tested, and proven to cohere. Below, the shape of the principle behind three of them.

stop here inline swarm
R2 Capability ladder

Capability scales sub-linearly with machinery. Climb one rung — inline → tool → retrieval → plan → subagent → swarm — and stop at the knee.

τ inline call
R3·M1 Tool value gate

A call must earn its place. Route to the tool, the reviewer or the subagent only once the expected loss it removes clears its cost.

serial chain plan-then-bind 1 call 8 calls
R6 Plan, then bind

Plan in placeholders; bind the calls last. Independent tool and sub-agent calls run in parallel, not down a chain — latency stays flat as the work fans out.

The decision — every call is the same inequality.

Add a tool? Spawn a reviewer? Branch wider? Retry once more? Under the hood fabius asks one question — does the expected loss removed beat the cost of the machinery? That single threshold governs the twenty-two proven routing rules — and the researched frontier layer beyond them. Scout wide, strike narrow — as arithmetic.

𝔼[L | skip] 𝔼[L | act] > c → engage
𝔼[L | skip]expected loss without it𝔼[L | act]expected loss with itcthe cost of the machinery
Act only when the value clears the cost.
cost cskip — pure overheadengagevalue of information →net value of acting

The gap on the left is the value of information. Below the threshold the machinery is pure overhead; fabius stays inline. (rules R3 · R7 · M1 · M4 — one object, different machinery.)

Worked example — should fabius add a reviewer?

  1. The author missesp₁ = 30%
  2. An independent reviewer missesp₂ = 40%
  3. Independent ⇒ both missp₁·p₂ = 0.30×0.40 = 0.12
  4. Expected error30% → 12%
one pass30%
two passes12%

18 points of loss removed — more than one agent costs. So fabius spawns the reviewer: two decorrelated passes beat one. (rule M1)

Process picks how, domain picks whatfabius-parcus, the lean core, runs beneath all of it. Twenty-two proven rules, each adversarially verified and shown to cohere.

04What you can hand it

One agent. Whichever model you choose.

Hand fabius the whole job. It reads the task, selects the skills, gives the operating plan to the chosen model, and holds the run to the same loop — scout, strike, prove, record.

decor

Ship a landing page

Design tokens, one accent, mobile-first — and live-verified with a headless screenshot before it’s called done.

praesidium

Audit a smart contract

STRIDE per trust boundary. Each finding ships a severity, a fix, and a regression test that runs red → green.

fortuna

Backtest a strategy

Out-of-sample, costs modeled, risk sized first. Analysis, never advice — and no look-ahead leak.

cohors

Orchestrate an agent

Least privilege, a precise output contract, and the smallest orchestration that holds — up to a swarm.

archivum

Remember a convention

One note, one index pointer, interlinked — recalled cold next session, so it never re-derives it.

ludus

Make a small game

Core loop first, deliberate juice, a jam-sized cut that actually ships — and is actually fun to play.

machina

Automate a workflow

Discover from the live schema, build incrementally, verify the wiring before it runs live — no silent miswire.

concilium

Convene a model council

N models answer blind → anonymized peer-review → a chairman synthesizes one better answer. For the costly calls.

disciplina

Diagnose a nasty bug

Reproduce → root cause → the minimal fix, locked by a regression test. Not a symptom patch.

FABIUS · CENTRAL INTELLIGENCE UNIT

scout wide · strike narrow

One stance handed to the agent. It investigates the whole field, then commits — fully — to the single battle that decides the war.

05Grounded in research

Decisions, not hand-waving.

fabius’s routing is our own research — a whole field of agent behaviour investigated, convened, and forged into a documented decision policy: twenty-two proven rules, each one derived and adversarially verified, coordinating fifteen skills without contradicting one another.

  • Climb one rung, stop at the knee. Capability scales sub-linearly with machinery — add the smallest sufficient rung (inline → tool → retrieval → plan → subagent → swarm), never jump to a swarm.
  • Refine on a real signal. A hard oracle (a test, a compiler) earns ~3 iterations; soft self-critique caps at 1–2; no signal ships once to review.
  • Proven to cohere. All twenty-two rules reduce to one expected-loss / value-of-information threshold — every proof adversarially verified, the extended theorem shipped with its exceptions printed in full.
Climb one rung, stop at the knee.
diminishing returnsfabius climbs to herethe kneeinlinetoolretrievalplansubagentswarmcapabilitymachinery →

The shape of a principle from fabius’s research: capability scales sub-linearly with machinery — climb to the knee, then stop.

06Talk to it

Talk to it. In any language.

Speak naturally. fabius detects the language, turns the request into a clean task, and reads the answer back in the right voice.

  • ~99 languagesDetected automatically — no language picker.
  • Clean transcriptsPunctuated, readable, ready to route.
  • Spoken answersHebrew comes back in a Hebrew voice.
  • Console or TelegramSpeak in the console or send a voice note.
  • Metered honestlyAbout $0.0005 per audio-minute in the console.
  • Browser fallbackFree, using the browser’s own language coverage.

07The model layer

Choose the model. Keep the brain.

Eight implemented runtime paths connect fabius to direct providers, model routers, and local inference. Name the model; fabius supplies the same scope, routing, skills, safety, memory, and verification contract, then keeps the run accountable from the first decision to the final proof.

fabiuscontrol plane 8 runtime paths · one brain
shared operating contractApplied before every model run.
  1. 01scope
  2. 02route
  3. 03specialize
  4. 04guard
  5. 05verify
  6. 06remember
Anthropic

Claude

supported

Fable 5 · Opus 4.8 · Sonnet 5 · Haiku 4.5

OpenAI

GPT

supported

GPT-5.6 Sol · Terra · Luna

Google

Gemini

supported

Gemini 3.5 Flash · 3.6 Flash · 3.5 Flash-Lite

Mistral

Mistral

supported

Large · Medium · Small

Groq

GPT-OSS

supported

GPT-OSS 120B · GPT-OSS 20B · low-latency path

Hugging Face

Open models

supported

Custom repository IDs · routed open-model inference

OpenRouter

Model router

supported

Custom model IDs · hundreds of routed model choices

Local runtime

Ollama

supported

Qwen Coder · Llama · private local model IDs

Named model familiesOne contract, across a wider model field.

Choose a custom model ID through OpenRouter or Hugging Face, or point Ollama at a local model. Catalog availability follows the route you select.

DeepSeekvia OpenRouter
Meta LlamaHF · local
QwenHF · router · local
Kimivia OpenRouter
Grokvia OpenRouter
Commandvia OpenRouter
Execution surfacesWorks where the task lives.
Local CLI Synapse Browser Telegram Grok Build

Provider, platform, and model-family marks identify compatible routes only. Availability depends on the selected catalog or local runtime; no affiliation or endorsement is implied.

08On your machine

The same agent. Now with hands.

Run fabius beside the repository: same router, rules, and memory — with filesystem access contained to the working directory and every irreversible action held for approval.

fabius · local runtime protected
$ fabius run "write the README this repo is missing"
$ fabius recon averya.co.il
$ fabius listen --owner npub1…
cwd boundarysecrets refusedproof required
  • 01
    Nothing extra to installNode and the repository. No build step.
  • 02
    Permission-firstRead-only until --act is explicit.
  • 03
    A hard safety floorPushes, production deploys, and recursive deletes still stop.
  • 04
    Contained by directoryThe working directory is a jail; key files stay out.
  • 05
    Runs what it wroteA failing exit code overrules a generous review.
  • 06
    Proven without spending75 checks, and not one spends a token.

ready when you are

Choose a model. Keep the same brain.

Hand fabius the job. It writes the operating contract, routes the right skills, and gives it to the model you selected. The model executes; fabius verifies and remembers.

1 hand fabius the task — choose a model engine
2 fabius instructs — the model executes — fabius proves

Private, cryptographically sealed brain · eight runtime paths · custom router and local model IDs · every run logged and reviewable.

09Questions

Frequently asked.

What is fabius?

fabius is an autonomous agent layer that sits above the model. It gives Claude, GPT, Gemini, Mistral, DeepSeek, Llama, Qwen, Kimi, Grok, Command, and other compatible models the same operating brain: instructions, routing, fifteen coordinated skills, memory, safety and verification. The selected model remains the execution engine; it follows the fabius contract from the task to the proof.

How do I run fabius?

Open the synapse console, hand fabius a task, and choose the model engine. fabius scopes the job, routes the right skills, gives the operating contract to the selected model, verifies what it returns, and records what mattered. Every run is logged and reviewable.

Can it run on my own machine?

Yes — and it is the same agent, not a cut-down one: same router, same rules, same contracts, read off disk and handed to the model. A console has no filesystem, so it cannot read the repository you are working in and the task leaves the building; running locally fixes both. It writes nothing and runs nothing until you allow it, the working directory is a boundary it cannot escape, secrets and key files are refused outright, and even in fully autonomous mode it still stops and asks before anything that cannot be undone — a push, a production deploy, a recursive delete. When it hands you code it runs that code first, and a failing exit overrules its own review. It also audits any domain you own without an API key, and can be reached by encrypted message with no server in between.

Can I talk to it?

Yes — in any language. Speak to it in the console instead of typing: it detects the language itself, so you never pick one from a list, and the transcript comes back punctuated and clean. It then reads its answer back out loud — Hebrew in a Hebrew voice. Being straight about the boundary: the mic that covers ~99 languages runs on the console’s own speech service — not on a model key — and costs about $0.0005 per audio-minute, billed to whoever runs the console; outside a console it falls back to the browser’s own speech engine — free, but that is the browser’s language coverage, not ~99. Connect it to Telegram and you can send it a voice note there too.

Which models does it run on?

fabius implements eight runtime paths: Anthropic, OpenAI, Google, Mistral, Groq, Hugging Face, OpenRouter and Ollama. Custom model IDs through the two routers, plus local IDs through Ollama, extend that field to DeepSeek, Llama, Qwen, Kimi, Grok, Cohere Command and many more models exposed by the selected catalog. Availability follows the provider or local runtime you choose; the same fabius brain remains in control.

Is the brain public?

No. fabius’s brain — the fifteen skills, the routing policy, the memory — is private and cryptographically sealed (SHA-256 + a Merkle root anchored to Bitcoin). The seal is proof of authorship if anyone ever copies it.

What does fabius add to the model?

It does not retrain or alter the base model. It adds the operating brain around it: instructions, routing, specialist skills, memory, safety and verification. The selected model follows that contract, so the same model can work more consistently and with less waste. In the benchmark — blind, judged against both a bare baseline and a generic “be concise” control — every capable tier (Fable 5, Sonnet 5, Opus 4.8) beats both controls on the four Claude models measured (the roster current at the 2026-07-01 run). Under fabius the smallest model passes 93% of real tests and factual checks vs 75.6% bare, and parameterized SQL goes 67.5% → 100%, on 20–35% less output. The fast tier’s dip on trivial one-liners remains printed as-is.

How is fabius evaluated?

Against its own written contract. The identity is fixed in the brain: fabius is an intelligence amplification layer, so the only fair question is whether the exact same model achieves better outcomes with less waste. The Fabius Benchmark Suite runs 100 neutral, production-shaped tasks in three modes — bare model, under the shipped fabius files, and with recalled memory added — scored by two blind judges and objective per-task checks. Latest run: the fast tier climbs 25.27 → 26.00 → 26.73 of 28 on 11–14% less output; the mid tier holds 93% quality on 10–12% less output. The misses are printed in the receipt, not hidden.

How is it different from telling the model to “be concise”?

That is exactly the control it was tested against — and it wins. fabius is structure, not brevity: a scope-control system that knows when to compress and when to expand. Method and caveats are in the whitepaper.

Can it clean AI marks off my content?

Yes — on content you own. Before anything ships, fabius runs a deterministic hygiene pass: invisible Unicode — zero-width characters, bidirectional marks, tag characters, the same character classes Trojan-Source attacks hide in — is stripped from generated text and code, and file metadata (EXIF, XMP, C2PA, document properties) is cleaned from images and documents with standard tools. Two boundaries, stated straight: statistical text watermarks live in the wording itself, so removing them means rewording — which degrades the copy — and no tool can certify that a vendor’s detector will fail afterwards, so fabius never promises that. The other direction is the point: fabius adds verifiable provenance to your own work — a content-bound seal anchored to Bitcoin — rather than erasing anyone else’s.