Build governed apps, workflows, documents and decks with shared company context.
Explore role workspaces
▥
Peak Readiness Command CenterA service-health app with SLOs, game days and approval-gated rollbacks.
App
⌘
Codex PR & Design ReviewDeterministic checks first; model judgment only when needed, with a human merge gate.
Workflow
▤
Post-Incident ReviewBlameless timeline, contributing factors and human-owned corrective actions.
Document
▣
Central Eng Quarterly ReviewA quarterly view of delivery, quality, reliability, developer experience and AI spend.
Slide Deck
Illustrative prototype. Public-facing demonstration with simulated data; no Costco systems are connected.
Peak Readiness Command Center
Illustrative
Build a holiday peak-readiness command center for Central Engineering: checkout and membership SLOs, game days, release risk and rollback approvals.
AI
I start with no access. I can ask for read-only signals without receiving a raw credential.
Gatekeeper: Observability + CI/CD Read service-level metrics, release records and game-day results. Changes and rollbacks require a named human approver.
Approve read-only access. Flag any action that changes production.
AI
I can assemble an illustrative Worker app from typed Gatekeeper bindings and calculate SLO and error-budget trends using code.
The example dashboard is ready. One checkout release is consuming error budget at 4.2× its planned rate. I drafted a rollback recommendation, but execution remains pending a human release owner. Two game days remain scheduled.
Review pull requests and design docs against our engineering Codex. Use cheap deterministic checks first and bring ambiguous architecture issues to a human owner.
AI
I can read the relevant Codex rules and request comment-only repository access.
Gatekeeper: Source Control + Engineering Codex Read pull requests and design docs; propose review comments. No merge, branch protection change or production write access.
AI
The workflow separates static checks from model judgment. It escalates only uncertain design decisions and waits for the owning team before blocking or approving a merge.
Illustrative run: 62 PRs and 8 design docs checked. Five need owner review; a pharmacy-service design doc has a single-region dependency that the Codex flags for resilience review. No merge was changed automatically.
Draft a blameless post-incident review for last week’s checkout disruption. Merge the incident timeline with alerts and change history, and flag missing evidence.
AI
I can only use incident records this requester is authorized to read.
Gatekeeper: Incident Management + Observability Read the example incident, alert timeline and related release metadata. Private responder notes remain restricted.
AI
I joined the incident, alerts and release events using deterministic timestamps. The example outage lasted 37 minutes; a connection-pool setting changed before the error spike. I’ve separated observed facts from hypotheses.
AI
The review is ready with four proposed actions. Owners must verify evidence and approve the two publication-ready items; I have not notified teams or modified the incident record.
Build a Central Engineering quarterly review: DORA, release quality, reliability, developer experience, AI adoption and cost, with priorities for the next quarter.
AI
I will request only aggregate, team-level metrics. Sensitive individual performance data is outside this workspace.
Gatekeeper: Delivery Metrics + AI Gateway Read-only aggregate delivery, test quality, incident and model-cost summaries for Central Engineering.
AI
The illustrative deck reconciles source periods before charting and labels targets separately from actuals. AI Gateway shows 89M tokens and $2,460 for Central Engineering, below its $3,000 demo cap.
AI
Five slides are ready. The roadmap prioritizes finishing two peak game days, extending the Codex review to tier-2 repositories and closing checkout rollback gaps. A human leader signs off before distribution.
Peak Readiness Command Center
App
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
99.95%
Checkout SLO target
4.2×
Checkout error-budget burn
7 / 9
Game days complete
1
Rollback awaiting approval
Approval required: Checkout API release R-218 is exhausting its error budget. Recommendation drafted; no production change has occurred.
Peak readiness: Two remaining game days are scheduled before the holiday change freeze.
Service-level overview
Membership sign-in
99.98%
Healthy
Checkout API
99.91%
Review
Fulfillment service
99.96%
Monitor
Game-day plan
Exercise
State
Gate
Payment provider failover
Complete
Observability review
Regional checkout failover
Scheduled
SRE owner approval
Warehouse event backlog
Scheduled
Central Eng approval
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
App blueprint
Worker-powered app · illustrative code, not a deployed Costco service
The view is generated from a sandboxed client and a Worker server. Its server-side logic calls approved, typed Gatekeeper capabilities; source credentials are never embedded in the generated app. Stateful apps can use Durable Objects with SQLite.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Resource boundaries
Source Control GatekeeperRead pull requests and design docs; comment proposals only.
CI/CD GatekeeperBuild and test results, read-only.
Engineering CodexVersioned organization context and standards; read-only to the agent.
AI GatewayModel routing, task budget and request-level audit for judgment steps.
Sharing & approvalsRe-check every viewer against all observed resources. Credentials stay with Gatekeepers; consequential actions need a human owner.
Post-Incident Review
Document
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Checkout API — Post-Incident Review
INC-DEMO-2291 · Example incident · 24 September 2026 · Blameless draft
Summary
A payment-token connection-pool setting introduced during a release increased checkout failures. The response team identified the change, authorized a rollback and confirmed error rates returned to baseline. This example reconstructs the response using synthetic events, not real incident data.
Impact measure
Example value
Interpretation
Incident duration
37 minutes
11:03–11:40 PT
Peak checkout errors
8.2%
First 12 minutes
Time to detect
6 minutes
Telemetry threshold fired
Time to mitigate
37 minutes
Rollback approved and verified
Contributing factors
Canary traffic did not reflect peak checkout load.
The connection-pool configuration lacked a high-load guardrail.
An alert route referenced a retired on-call rotation.
Corrective actions
Action
Human owner
State
Add peak-load canary validation
Checkout engineering
Approved
Test connection-pool saturation
Platform SRE
Approved
Audit paging ownership
Incident response
Awaiting review
Update rollback drill
Central Engineering
Awaiting review
Reader access is re-checked against every incident resource used to produce this review. Restricted notes are not included without permission.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Reconciled incident timeline
Synthetic events · times shown in Pacific Time
Time
Event
Source
11:03
Payment-token connection-pool setting released
CI/CD
11:09
Checkout errors cross alert threshold
Observability
11:15
Responder paged; on-call route corrected
Incident Management
11:23
Pool saturation correlated with errors
Traces
11:36
Human release owner approves rollback
Change record
11:40
Errors return to baseline; monitor continues
Observability
Hypothesis: unrepresentative canary traffic delayed detection of high-load pool saturation. Confirm against test evidence before publishing.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Resource boundaries
Incident Management GatekeeperAuthorized incident metadata, timeline and action items.
Observability GatekeeperScoped SLO, alert and tracing evidence.
CI/CD GatekeeperRead-only release and change records.
Confluence GatekeeperReference incident-review template; publishing needs a human.
Sharing & approvalsRe-check every viewer against all observed resources. Credentials stay with Gatekeepers; consequential actions need a human owner.
Central Eng Quarterly Review
Slide Deck
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Slide 1 of 5
Central Engineering Quarterly Review
Q3 2026 · Costco OS · Illustrative prototype
Slide 2 of 5 · Delivery
Delivery performance
18/wk
Deploy frequency
31m
Lead time
0.8%
Change failure rate
29m
Time to restore
Illustrative team-level DORA metrics; verify source and period before presenting.
Slide 3 of 5 · Reliability and quality
Reliability and quality
Signal
Example actual
Next review
Critical service availability
99.96%
Checkout error budget
CI pass rate
96.8%
Flaky-test cleanup
Peak game days
7 of 9 complete
Two remaining drills
Tier-1 Codex coverage
85%
Extend to tier-2
Slide 4 of 5 · Developer experience and AI
Developer experience and governed AI
62
PRs in sample Codex run
89M
AI tokens, Central Eng
$2,460
AI spend of $3,000 cap
Demo figures only; model usage aggregated at team scope. No individual developer scoring.
Slide 5 of 5 · Next-quarter priorities
Decisions and priorities
Peak readiness: complete the last two game days before the holiday change freeze.
Release assurance: codify checkout rollback and canary load validation.
Codex coverage: extend PR and design review to tier-2 repositories with an owner gate.
AI efficiency: use deterministic checks first; track usage and quality in AI Gateway.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Deck source ledger
Illustrative sources · Q3 2026 · no live connections
Slide
Source boundary
Check
Delivery
Delivery Metrics Gatekeeper
Q3 team-level aggregate
Quality
CI/CD + incident records
Same reporting period
Reliability
Observability + game-day results
Service owners verify
AI cost
AI Gateway team summary
89M tokens, $2,460 of $3,000 cap
Next priorities
Engineering Codex + review actions
Leader approval needed
Distribution is approval-gated. A viewer must have permission to every observed source used for the deck.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Resource boundaries
Delivery Metrics GatekeeperAuthorized team-level DORA and developer-experience aggregates.
Observability + CI/CD GatekeepersService SLOs, release health and quality at the same reporting cadence.
AI GatewayAggregate model requests, token volume, spend and budget for Central Engineering.
Engineering CodexCurated architecture and review principles, versioned and read-only.
Sharing & approvalsRe-check every viewer against all observed resources. Credentials stay with Gatekeepers; consequential actions need a human owner.
Integrations
Organization-wide Gatekeepers expose scoped capabilities, hold credentials and record access across workspaces.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Gatekeepers
G
Google Workspace
Calendar, mail, files, Docs, Sheets and Slides
G
Google Chat
Read scoped spaces and draft team notifications
J
Jira
Issues, delivery status and architecture reviews
C
Confluence
Read approved documentation and engineering standards
S
Source Control
Repository metadata, design docs and pull requests
O
Observability
Service SLOs, traces and error-budget signals
C
CI/CD
Build status, release records and rollback plans
I
Incident Management
Incident timelines, ownership and action items
D
Delivery Metrics
DORA and quality data at authorized team scope
C
Cloudflare AI Gateway
Model routing, aggregate usage and spend
S
ServiceNow
Changes, tickets and service ownership
S
SAP
Finance, procurement and supply-chain data
S
Salesforce
Authorized member and partner CRM records
S
Snowflake
Governed analytics and aggregate reporting
MCP Server Portals
Team-specific MCP servers are discovered through organization portals; authorization remains scoped to the caller.
Engineering tools
Repository, CI and review capabilities
Scoped
Operations
Incidents, on-call and change tracking
Scoped
Customer experience
Member journeys and service feedback
Scoped
Supply chain
Supplier and fulfillment insights
Scoped
Finance
Aggregate budgets and approved spend
Scoped
People operations
Role-based policy and onboarding context
Scoped
Organization Context
Shared, versioned knowledge available to authorized workspaces across Costco — not tied to one role.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
md
company-strategy.md
Mission, operating model and outcome definitions
md
brand-and-member-communications.md
Voice, accessibility and member-facing communication
md
security-standards.md
Identity, secure development and protective controls
md
engineering-codex.md
Design review rules, ownership and architectural constraints
md
architecture-principles.md
Resilience, service design and review templates
md
sre-slo-standards.md
Service level objectives, error budgets and game days
md
incident-response-playbook.md
Blameless reviews, escalation and evidence handling
md
data-classification.md
Data types, retention and authorized use
md
responsible-ai-standard.md
Model evaluations, risk tiers and human approval
md
privacy-and-member-data.md
Member privacy and sensitive data boundaries
md
member-experience-playbook.md
Membership journey and service standards
md
supply-chain-procedures.md
Procurement, suppliers, inventory and fulfillment
md
hr-policies.md
People operations, onboarding and employee policies
md
financial-reporting.md
Budgeting, financial controls and reporting
Skills
Reusable organization-wide workflows. A human owner stays accountable for every output.
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Name
Description
Group
Source
meeting-prep
Build an agenda from authorized calendar, CRM and document context
General
Prototype library
weekly-operating-review
Summarize decisions, owners, risks and open follow-ups
General
Prototype library
incident-response
Assemble scoped evidence and draft a blameless review
Security
Prototype library
vendor-assessment
Compare suppliers against approved security requirements
Security
Prototype library
compliance-evidence
Collect authorized control evidence for human review
Security
Prototype library
architecture-review
Draft an architecture decision with Codex criteria
IT & Architecture
Prototype library
codex-pr-review
Check pull requests and design docs; flag human decisions
IT & Architecture
Prototype library
change-impact
Map service dependencies before a proposed change
IT & Architecture
Prototype library
api-catalog
Document services, endpoints, owners and health
IT & Architecture
Prototype library
peak-readiness
Review SLOs, game days and rollback approvals
Operations
Prototype library
runbook-automation
Turn approved steps into deterministic checks
Operations
Prototype library
supplier-scorecard
Summarize supplier quality and delivery at authorized scope
Operations
Prototype library
model-evaluation
Compare model quality, latency and task-level risks
Data & AI
Prototype library
ai-usage-review
Analyze model traffic and team budgets
Data & AI
Prototype library
member-insights
Summarize aggregate, permitted member experience signals
Member Experience
Prototype library
service-feedback
Synthesize support trends and actionable themes
Member Experience
Prototype library
budget-analysis
Explain budget variances from approved finance aggregates
Finance
Prototype library
cost-optimization
Identify infrastructure cost opportunities for review
Finance
Prototype library
job-posting-draft
Draft role descriptions from approved people policies
HR
Prototype library
onboarding-guide
Assemble approved team and policy onboarding references
HR
Prototype library
policy-compare
Surface changes for legal and compliance owners
Legal
Prototype library
contract-brief
Prepare an authorized summary for legal review
Legal
Prototype library
Profile
Illustrative account information for this public prototype.
Account
Demo User
No personal information is stored
Display name
Demo User
User ID
demo.user@example.com
AI Gateway
Illustrative scenario data for simulated model routes, controls, and usage — one console.
Illustrative scenario. Providers, models, traffic, latency, spend, users, teams, budgets, and controls are simulated; they do not describe Costco systems or activity.
Requests
128,400
▲ 11% vs last mo
Tokens
342M
▲ 8% vs last mo
Est. spend
$9,120
76% of budget
Cache-hit
27%
▲ saves ~$2.4k
Error rate
0.6%
▼ 0.2 pts
p50 latency
480 ms
across providers
Illustrative Model Traffic
This month
Model
Route
Tokens
Spend
Share
p50 latency
Llama 3.3 70B
Workers AI
156M
$2,140
42%
310 ms
Claude
via AI Gateway
98M
$3,980
24%
720 ms
GPT-4o
via AI Gateway
61M
$2,510
18%
640 ms
Workers AI embeddings (bge)
Workers AI
27M
$490
16%
40 ms
Spend vs. Budget
1 day remaining
$9,120spent of $12,000 cap
76%
On track · ~$2,880 left with 1 day
Illustrative Users
Demo User 0142M tok $1,180
Demo User 0231M tok $960
Demo User 0328M tok $840
Demo User 0422M tok $610
Illustrative Usage by Workspace / Team
342M tokens total
Data & AI
121M tokens · $3,240
Central Engineering
89M tokens · $2,460
Member Experience
62M tokens · $1,510
Merchandising & Supply Chain
41M tokens · $1,020
Security & Compliance
29M tokens · $890
Governance
Illustrative guardrail settings modeled with Gatekeepers + AI Gateway, resource-scoped access, audit trails, and human approval.
Illustrative settings. Every model, limit, retention period, approval, and control below is simulated; no Costco policy or configuration is connected.
Per-team allowed models
Restrict which providers each workspace can call.
Llama 3.3ClaudeGPT-4o+ embeddings
Monthly spend caps
Hard limits per team; agents stop before overrun.
Data & AI $4,000Central Engineering $3,000Merchandising & Supply Chain $2,000Security & Compliance $2,000
PII redaction
Strip sensitive fields from prompts before they leave.
Enabled
Prompt / response logging
Full request logs retained for audit & review.
Enabled · 90-day retention
Rate limits
Per-team request ceilings to protect budgets.
600 req / min|burst 1,000
Raise Merchandising & Supply Chain cap to $3,000
Simulated change queued by an agent — needs a human sign-off.