Building an Operating System for AI Agents
Terminus Intelligence · September 13, 2026
Every AI product right now is a chat window. You type, it answers, and when the conversation ends, the work evaporates into a scroll buffer. We spent a year building the opposite bet: that agents need an operating system — a place with files, windows, schedules, and addresses — more than they need a better chat box. This is what we learned building Terminus.
The OS metaphor, taken literally
Terminus renders a desktop in the browser: a menu bar, a dock, overlapping windows, and a file system with Desktop, Documents, Downloads, and Trash. People assume this is nostalgia. It isn't — it's a contract.
The thing chat products can't give you is a place where work accumulates. An agent that researches your competitors every morning has to put the report somewhere the next agent — and you, and the apps you install — can find it. The desktop metaphor is thirty years of shared vocabulary for exactly that problem: files are the interface between programs that don't know about each other. We didn't adopt the metaphor for charm; we adopted it because "agents and apps compose over a file system" is a real architecture, and the desktop is its honest UI.
Files, not rows
The deepest decision in Terminus: apps store state as files in the user's space, not as rows in app-owned tables.
Every user gets a per-user, per-app data directory. When you install a notes app, your notes are files in your directory that the app has been granted access to — not rows in the app's database that you've been granted access to. The inversion matters three ways.
First, replaceability: you can swap an app's interface without losing your data, because the files outlive the app. Second, inspectability: "what does this app know about me" is a folder you can open, not a support ticket. Third, composability: your research agent's output is directly readable by your writing agent, your dashboard app, and your own eyes, because it's a file in a directory — the universal interface.
Four kinds, one catalog
Everything publishable in Terminus is an artifact with a stable address — @publisher/slug — and there are exactly four kinds: skills (reusable capabilities a model can invoke), apps (windowed programs over your files), agents (standing workers with schedules and tool grants), and services (metered operations like code execution or image generation).
One catalog, one address grammar, one publishing pipeline — from the CLI or the in-browser Studio. The uniformity is load-bearing: search ranks all four kinds in one index, the Store renders them with one card grammar, and an agent can discover and invoke a skill by searching the same catalog a human browses. Every time we tried to special-case a kind, the composition broke somewhere else.
Agents that work while you don't
A Terminus agent is not a chat session with a cron job stapled on. It's a first-class object: an address, a purpose, a schedule or trigger written in plain language, and a set of scoped tool grants — like reading your email or searching the web — that bound what it can touch.
The trust feature that mattered most in practice is a mundane one: an agent run that dies partway through keeps the work it already did. The user sees what was done and what wasn't, and the next run continues from evidence rather than starting over. Long-running autonomy isn't a model capability; it's a system property, and the system has to be built for the unhappy path.
The model is a config field
Terminus routes every completion — desktop chat, agents, apps — through one OpenAI-compatible gateway, and the model is just a string: a GPT model, a Claude model, DeepSeek, Kimi. Usage is metered per request, and pricing is tracked per provider — including off-peak windows, which matter a great deal when an agent runs four hundred times a day.
The consequence we didn't fully anticipate: model-agnosticism changes what people build. An agent that's economically absurd on a frontier model at list price is routine on an off-peak reasoning model. The gateway isn't a convenience feature; it's what makes "agents running around the clock" a sane default instead of a demo.
What we'd tell you if you're building one
The file system is the product: every hard problem — permissions, composition, data ownership, guest mode — became tractable when it became a file-system problem. Addresses beat links: one identity grammar for every artifact meant search, install, invocation, and attribution all got solved once. And design for the unhappy path: anything that runs longer than a request will die mid-flight in production, and what your system does then is what users learn to trust — or not.
Terminus is in beta at terminus.build — an invite-only waitlist while we harden the platform. If building on an agent operating system sounds like your kind of problem, join it, or write to early-access@terminus.build.