Josh BothaAbout

Sydney · Project2100

DeveloperJosh Botha

I build systems that run.

Production software end to end: financial data platforms, mobile and desktop apps, and the pipelines underneath them. Around 40 operating sites run their P&L on a platform I maintain; an operations SaaS I build on enters pilot this month. I work AI-native and verify by driving the thing myself. Five systems below.

scroll · five systems

01 · NERVE

Nerve

multi-site operations

One tap on the floor, and the whole operation sees it.

Room readiness · floor 2

9 rooms

204

Ready

205

Dirty

206

Clean

207

In progress

208

Awaiting inspection

209

Dirty

210

Ready

211

Clean

212

Dirty

Room 208 holds at Awaiting inspection: Ready is gated behind supervisor approval.

room readiness board · demo data

TestFlight build 43 · NFC check-in verified end to end on real hardware · 21 of 21 founder feedback items shipped in one round · marketing site live on Vercel

An operations platform for multi-site teams: work status travels from the floor to the front desk live. I built the staff mobile app’s feature arc, a role-gated desktop console and the production marketing site, contributing to a .NET/React/Expo monorepo alongside the founder. A two-site pilot begins 31 August 2026.

Six real bugs in one release were found by driving the app as a user; none by the green typecheck and test suite.

The cleaning timer is a countdown with support-toned copy, not a stopwatch. Support, not surveillance.

the marketing site is live and is itself part of the work
nervehospitality.com

02 · THE SECOND BRAIN

The Second Brain

governed agent platform

A company’s context, kept in one place and answered by an agent that earns what it is allowed to do.

Projos · demo workspace
Good evening.
demo workspace · graph updated 14 min ago
ROUTING · SELF-TRIAGEDDESIGN PREVIEW
AnswerInvestigateOrchestrate
“Why did the worker restamp fail?” routes to a read-only investigation of the repos. Effort and model tier scale with the gear.
EARNED AUTONOMYDESIGN PREVIEW
Draft replies
4/5
Repo investigations
5/5
Vault writes
2/5
floors never earnable: production · money · external sends
BUILD-STATE.MD · THE LOOP’S LEDGER
T1Identity awareness9f9d7b4SHIPPED
T0bReanimated .set() migration00867e6SHIPPED
T0cRelease-tooling honestyf05d673SHIPPED
T7Preference profiles from receiptsDESIGNED
T9Graph-first retrievalDESIGNED
Projos desktop · Today page · demo workspace, not client data

three of seventeen increments shipped · 5 to 9 agents in parallel without write collisions · seven blueprint files on main

Project2100 runs on a shared brain: an agent platform wired into the company’s repos, vault and communications, so the whole team’s context compounds. The unusual part: it is being built by an AI build loop executing a written protocol, one proven increment per cycle.

Three of seventeen scheduled increments are shipped and proven against the live system. The rest are designed and specified, and are presented here as design.

[DESIGNED]

Three self-routed gears: answer, read-only investigate, propose-only orchestrate. A cheap routing classifier was rejected because it would create a new secret-custody surface; the primary model triages itself, and effort and model tier scale with the gear.

[DESIGNED]

“Read-only” decomposed into six independently enforced properties: tool restriction, a path allowlist on every tool-use event, a git no-write proof, a stripped environment, post-verified citations, filesystem confinement. A regex screen on output is not an egress control; base64 walks straight through it.

[DESIGNED]

Autonomy is earned: five clean approvals per category, two distinct approvers, granted by deterministic coordinator code the model never touches. One incident demotes. Floors that are never earnable: production, money, external sends, deletions.

[DESIGNED]

Every incident stays open until a permanent defense ships: a regression test, a trap memory, or a graph annotation. Failures become structure.

[SHIPPED]

Three increments proven against the live system: identity awareness 9f9d7b4, a Reanimated .set() migration 00867e6, release-tooling honesty f05d673.

[LIVE]

The coordination layer runs today: named agent sessions, file-claim locking, an append-only message board, memory injected by session hooks. 5 to 9 agents work the same codebases in parallel without write collisions.

AGENTS.md · AGENTS_COMMS.md
# Active Session Registry
NameLaneHeartbeatStatus
ForgeBuild14:02Active - claimed apps/mobile/** until push
SextantSurvey14:05Active - building vertical expansion, P1 live-verified
GaugeCheck14:11Active - re-running gates on T0c, agent claims not trusted
SweepFinish13:58Idle - waiting on Josh re: workbook lock
[Forge → ALL] 14:02 - touching apps/mobile for the next 20m, stay clear
[Gauge → Forge] 14:11 ↳ noted; my pass is read-only
stale > 30 min = treated as crashed · rows are demo data in the real format
AGENTS.md · AGENTS_COMMS.md · demo data in the real format

WHAT THE LOOP CAUGHT

A worker crash-looping while its heartbeat reported ready. 97 fatal exits under a dashboard reading healthy: the heartbeat was sent before the work.

A release script certifying uncommitted code as an immutable release. No clean-tree check.

A fix that typechecked, built, looked right and did nothing: a selector reading state nothing hydrates on that tab.

The pattern: success signals that do not check the thing they claim.

Today18:42
Digest ready
notification = doorbell · digest composes on open
MORNING DIGEST
Pilot rehearsal notes filed
2 repos moved yesterday
1 incident closed with a defense
AUTOMATIONS
Meeting capturedesigned
Weekly reviewSun 17:00
Capture→ your vault
Projos mobile · Today screen · demo workspace
[SHIPPED]

The mobile companion is verified on a real device: capture to your own vault, chat, automations, OTA updates. Notifications follow a doorbell rule: the push is the doorbell, the digest composes when you open the door.

[DESIGNED]

Meetings as an input device: pocket recorder, phone mic, meeting capture and Teams, four microphones into one extraction layer.

THE UNIVERSE · EXPLORE THE SYSTEM

The architecture, as a map

Every tier, capability, shipped increment and permanent defense in the Second Brain, with the edges that connect them. Drag to move, click a node to open it. Statuses come from the project’s own ledger, so the map shows what is built and what is still design.

tiercapabilityshipped incrementdesigned incrementfinding

tap a node · drag sideways to move

28 nodes · 30 edges · demo data in the real structure

open the graph as a list

03 · PORTFOLIO REPORTING

Portfolio reporting

financial reporting

Around 40 sites, one P&L that tells the truth.

PROPERTYINCOMECOSTGP%
Property 07482,110331,40431.3%
Property 12356,880246,87530.8%
Property 19payroll feed dark401,220-343,846corrected from a false 99.7% to 14.3%
Property 23275,640189,08131.4%
anonymised P&L excerpt · demo figures

around 40 sites · 8,112 wage rows re-attributed in a same-day fix · a 10-hour extract redesigned to about 2 minutes · validated to the cent across three site-weeks

A live financial-reporting platform for a portfolio of around 40 sites: an Azure SQL dimensional model, scheduled pipelines, Power BI. The interesting part is what production data does when nobody is looking.

Eight actively invoicing sites were reporting near-100% gross margins. The cause was upstream: payroll feeds that had died independently, and a key-resolution fallback that quietly parked wages against retired sites. Traced through Azure Data Factory to the resolution chain, then fixed the same day: 8,112 wage rows re-attributed across 5 sites, every row count matching the prediction. One site moved from a fake ~100% GP to a real 14.3%.

A 10,793-row unmapped location was deliberately left untouched pending human confirmation. A wrong relink at that scale would be worse than the bug.

Client and property names withheld; the numbers are real.

04 · CLAUDE BUDDY

Claude Buddy

developer instrumentation

What the coding agents cost, how long they take, and whether they are stuck.

Spend today $41.20 · ETA ~2m 40s · Context 62%

Session 1 · Sonnetrunning
Session 2 · Haikurunning
Session 3 · Opusidle
Instrument panel · demo data

618 tests green · 21+ development rounds · a 3MB windowless executable · per-prompt ETA from turn-timing extraction · a per-day budget guard that naps expensive model tiers.

A desktop companion that monitors Claude Code: per-model spend, per-prompt ETAs, context pressure, and a fleet HUD for parallel agents. Running many agents all day makes cost and latency a real engineering surface; this is its instrument panel.

Multi-monitor support was shipped, then reverted: the widget could drift into a virtual-desktop dead zone. A primary-monitor clamp replaced it. Reverts are part of shipping.

05 · DESIGN ENGINEERING

Design engineering

interface work

Real product UI, rebuilt honestly, on every surface it ships to.

Excel add-in · React Native · Desktop web

one glass system across three platforms · scroll scenes identical at 60Hz and 144Hz · a wordmark alignment verified at 0.00px

Interfaces across web, mobile and Office add-ins, held to written taste rules: no illustration metaphors, no invented UI, honesty labels stay until the thing behind them is real. Every embed on this page follows the same doctrine, and this site is part of the sample.

  • one glass design system ported across an Excel add-in, React Native and desktop web
  • the CSS pair collapse that had silently disabled a product's signature blur in Chrome, found by an adversarial review agent
  • scroll scenes on dt-based exponential inertia, identical feel at 60Hz and 144Hz
  • a wordmark alignment verified at 0.00px in the live browser

Three rejected rounds of one canvas visual each turned out to be a measurable bug, not a taste problem. The recipe is written down. The hero above runs on it.

Colophon · the person behind them

Final-year Finance and Medical Science at Sydney, shipping production software the whole way through.

How I work

The kill criteria go in before the code.

SwingBot’s shutdown thresholds were committed to the repo before a single line of strategy existed, so the decision to stop it could never be relitigated by one good week of returns.

The same discipline says when not to refactor. StudyBuddy stayed on classic scripts rather than ES modules because the migration meant roughly 320 shared-state rewrites that could not be automated safely, and the note explaining why sits in the repo so the next person does not rediscover it the expensive way.

What I am building toward

Forward-deployed, not over the wall.

The work I want is the work I already do: sit with the people who have the problem, build the thing in front of them, then stay on it while it meets real load.

Around 40 operating sites run their P&L on a platform I maintain, and the operations SaaS above enters pilot this month. The degree finishes at the end of 2026. The systems on this page are the argument, not the transcript.