Costco OS

What are we working on?

Build governed apps, workflows, documents and decks with shared company context.
Explore role workspaces
▥
Peak Readiness Command CenterA service-health app with SLOs, game days and approval-gated rollbacks.
App
⌘
Codex PR & Design ReviewDeterministic checks first; model judgment only when needed, with a human merge gate.
Workflow
▤
Post-Incident ReviewBlameless timeline, contributing factors and human-owned corrective actions.
Document
▣
Central Eng Quarterly ReviewA quarterly view of delivery, quality, reliability, developer experience and AI spend.
Slide Deck
Illustrative prototype. Public-facing demonstration with simulated data; no Costco systems are connected.
Peak Readiness Command Center
Illustrative
Build a holiday peak-readiness command center for Central Engineering: checkout and membership SLOs, game days, release risk and rollback approvals.
AI
I start with no access. I can ask for read-only signals without receiving a raw credential.
Gatekeeper: Observability + CI/CD
Read service-level metrics, release records and game-day results. Changes and rollbacks require a named human approver.
Approve read-only access. Flag any action that changes production.
AI
I can assemble an illustrative Worker app from typed Gatekeeper bindings and calculate SLO and error-budget trends using code.
Illustrative code
const [slos, releases, drills] = await Promise.all([ env.OBSERVABILITY.getSLOs({ services: ["checkout", "membership", "fulfillment"] }), env.CICD.getReleases({ window: "24h", access: "read" }), env.GAME_DAYS.list({ period: "peak-2026" }) ]); app.render(PeakReadiness, { slos, releases, drills });
AI
The example dashboard is ready. One checkout release is consuming error budget at 4.2× its planned rate. I drafted a rollback recommendation, but execution remains pending a human release owner. Two game days remain scheduled.
Review pull requests and design docs against our engineering Codex. Use cheap deterministic checks first and bring ambiguous architecture issues to a human owner.
AI
I can read the relevant Codex rules and request comment-only repository access.
Gatekeeper: Source Control + Engineering Codex
Read pull requests and design docs; propose review comments. No merge, branch protection change or production write access.
AI
The workflow separates static checks from model judgment. It escalates only uncertain design decisions and waits for the owning team before blocking or approving a merge.
Illustrative code
const rules = await env.CONTEXT.read("engineering-codex.md"); const changes = await env.SOURCE_CONTROL.listReviews({ access: "read" }); const facts = runDeterministicChecks(changes, rules); const ambiguous = facts.filter(f => f.needsJudgment); const recommendations = await model.review(ambiguous, rules); return queueForHumanOwner(recommendations);
AI
Illustrative run: 62 PRs and 8 design docs checked. Five need owner review; a pharmacy-service design doc has a single-region dependency that the Codex flags for resilience review. No merge was changed automatically.
Draft a blameless post-incident review for last week’s checkout disruption. Merge the incident timeline with alerts and change history, and flag missing evidence.
AI
I can only use incident records this requester is authorized to read.
Gatekeeper: Incident Management + Observability
Read the example incident, alert timeline and related release metadata. Private responder notes remain restricted.
AI
I joined the incident, alerts and release events using deterministic timestamps. The example outage lasted 37 minutes; a connection-pool setting changed before the error spike. I’ve separated observed facts from hypotheses.
AI
The review is ready with four proposed actions. Owners must verify evidence and approve the two publication-ready items; I have not notified teams or modified the incident record.
Build a Central Engineering quarterly review: DORA, release quality, reliability, developer experience, AI adoption and cost, with priorities for the next quarter.
AI
I will request only aggregate, team-level metrics. Sensitive individual performance data is outside this workspace.
Gatekeeper: Delivery Metrics + AI Gateway
Read-only aggregate delivery, test quality, incident and model-cost summaries for Central Engineering.
AI
The illustrative deck reconciles source periods before charting and labels targets separately from actuals. AI Gateway shows 89M tokens and $2,460 for Central Engineering, below its $3,000 demo cap.
AI
Five slides are ready. The roadmap prioritizes finishing two peak game days, extending the Codex review to tier-2 repositories and closing checkout rollback gaps. A human leader signs off before distribution.
Peak Readiness Command Center
App
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
99.95%
Checkout SLO target
4.2×
Checkout error-budget burn
7 / 9
Game days complete
1
Rollback awaiting approval
Approval required: Checkout API release R-218 is exhausting its error budget. Recommendation drafted; no production change has occurred.
Peak readiness: Two remaining game days are scheduled before the holiday change freeze.
Service-level overview
Membership sign-in
99.98%
Healthy
Checkout API
99.91%
Review
Fulfillment service
99.96%
Monitor
Game-day plan
ExerciseStateGate
Payment provider failoverCompleteObservability review
Regional checkout failoverScheduledSRE owner approval
Warehouse event backlogScheduledCentral Eng approval
Codex PR & Design Review
Workflow
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
62
PRs checked
8
Design docs checked
5
Owner reviews needed
0
Autonomous merges
Review pipeline
1
Trigger & scope

New PR or design doc. Read only the resources granted by Source Control and Context Gatekeepers.

2
Deterministic checks

Lint, dependency, test, ownership and Codex rules run in code; no model call for known facts.

3
Selective model judgment

Architecture tradeoffs and ambiguous exceptions route through AI Gateway with a bounded budget.

4
Human decision

Findings are proposed as comments; a designated owner decides on merge, exception or remediation.

No direct merge permission. Only an authorized engineer can accept or reject a recommendation.
Post-Incident Review
Document
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.

Checkout API — Post-Incident Review

INC-DEMO-2291 · Example incident · 24 September 2026 · Blameless draft

Summary

A payment-token connection-pool setting introduced during a release increased checkout failures. The response team identified the change, authorized a rollback and confirmed error rates returned to baseline. This example reconstructs the response using synthetic events, not real incident data.

Impact measureExample valueInterpretation
Incident duration37 minutes11:03–11:40 PT
Peak checkout errors8.2%First 12 minutes
Time to detect6 minutesTelemetry threshold fired
Time to mitigate37 minutesRollback approved and verified

Contributing factors

  • Canary traffic did not reflect peak checkout load.
  • The connection-pool configuration lacked a high-load guardrail.
  • An alert route referenced a retired on-call rotation.

Corrective actions

ActionHuman ownerState
Add peak-load canary validationCheckout engineeringApproved
Test connection-pool saturationPlatform SREApproved
Audit paging ownershipIncident responseAwaiting review
Update rollback drillCentral EngineeringAwaiting review
Reader access is re-checked against every incident resource used to produce this review. Restricted notes are not included without permission.
Central Eng Quarterly Review
Slide Deck
Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Slide 1 of 5

Central Engineering Quarterly Review

Q3 2026 · Costco OS · Illustrative prototype

Slide 2 of 5 · Delivery

Delivery performance

18/wk
Deploy frequency
31m
Lead time
0.8%
Change failure rate
29m
Time to restore

Illustrative team-level DORA metrics; verify source and period before presenting.

Slide 3 of 5 · Reliability and quality

Reliability and quality

SignalExample actualNext review
Critical service availability99.96%Checkout error budget
CI pass rate96.8%Flaky-test cleanup
Peak game days7 of 9 completeTwo remaining drills
Tier-1 Codex coverage85%Extend to tier-2
Slide 4 of 5 · Developer experience and AI

Developer experience and governed AI

62
PRs in sample Codex run
89M
AI tokens, Central Eng
$2,460
AI spend of $3,000 cap

Demo figures only; model usage aggregated at team scope. No individual developer scoring.

Slide 5 of 5 · Next-quarter priorities

Decisions and priorities

Peak readiness: complete the last two game days before the holiday change freeze.
Release assurance: codify checkout rollback and canary load validation.
Codex coverage: extend PR and design review to tier-2 repositories with an owner gate.
AI efficiency: use deterministic checks first; track usage and quality in AI Gateway.

Integrations

Organization-wide Gatekeepers expose scoped capabilities, hold credentials and record access across workspaces.

Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
Gatekeepers
G
Google Workspace
Calendar, mail, files, Docs, Sheets and Slides
G
Google Chat
Read scoped spaces and draft team notifications
J
Jira
Issues, delivery status and architecture reviews
C
Confluence
Read approved documentation and engineering standards
S
Source Control
Repository metadata, design docs and pull requests
O
Observability
Service SLOs, traces and error-budget signals
C
CI/CD
Build status, release records and rollback plans
I
Incident Management
Incident timelines, ownership and action items
D
Delivery Metrics
DORA and quality data at authorized team scope
C
Cloudflare AI Gateway
Model routing, aggregate usage and spend
S
ServiceNow
Changes, tickets and service ownership
S
SAP
Finance, procurement and supply-chain data
S
Salesforce
Authorized member and partner CRM records
S
Snowflake
Governed analytics and aggregate reporting

MCP Server Portals

Team-specific MCP servers are discovered through organization portals; authorization remains scoped to the caller.

Engineering tools
Repository, CI and review capabilities
Scoped
Operations
Incidents, on-call and change tracking
Scoped
Customer experience
Member journeys and service feedback
Scoped
Supply chain
Supplier and fulfillment insights
Scoped
Finance
Aggregate budgets and approved spend
Scoped
People operations
Role-based policy and onboarding context
Scoped

Organization Context

Shared, versioned knowledge available to authorized workspaces across Costco — not tied to one role.

Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
md
company-strategy.md
Mission, operating model and outcome definitions
md
brand-and-member-communications.md
Voice, accessibility and member-facing communication
md
security-standards.md
Identity, secure development and protective controls
md
engineering-codex.md
Design review rules, ownership and architectural constraints
md
architecture-principles.md
Resilience, service design and review templates
md
sre-slo-standards.md
Service level objectives, error budgets and game days
md
incident-response-playbook.md
Blameless reviews, escalation and evidence handling
md
data-classification.md
Data types, retention and authorized use
md
responsible-ai-standard.md
Model evaluations, risk tiers and human approval
md
privacy-and-member-data.md
Member privacy and sensitive data boundaries
md
member-experience-playbook.md
Membership journey and service standards
md
supply-chain-procedures.md
Procurement, suppliers, inventory and fulfillment
md
hr-policies.md
People operations, onboarding and employee policies
md
financial-reporting.md
Budgeting, financial controls and reporting

Skills

Reusable organization-wide workflows. A human owner stays accountable for every output.

Illustrative prototype. Scenarios, connections and metrics are simulated; no Costco systems or live customer data are connected.
NameDescriptionGroupSource
meeting-prepBuild an agenda from authorized calendar, CRM and document contextGeneralPrototype library
weekly-operating-reviewSummarize decisions, owners, risks and open follow-upsGeneralPrototype library
incident-responseAssemble scoped evidence and draft a blameless reviewSecurityPrototype library
vendor-assessmentCompare suppliers against approved security requirementsSecurityPrototype library
compliance-evidenceCollect authorized control evidence for human reviewSecurityPrototype library
architecture-reviewDraft an architecture decision with Codex criteriaIT & ArchitecturePrototype library
codex-pr-reviewCheck pull requests and design docs; flag human decisionsIT & ArchitecturePrototype library
change-impactMap service dependencies before a proposed changeIT & ArchitecturePrototype library
api-catalogDocument services, endpoints, owners and healthIT & ArchitecturePrototype library
peak-readinessReview SLOs, game days and rollback approvalsOperationsPrototype library
runbook-automationTurn approved steps into deterministic checksOperationsPrototype library
supplier-scorecardSummarize supplier quality and delivery at authorized scopeOperationsPrototype library
model-evaluationCompare model quality, latency and task-level risksData & AIPrototype library
ai-usage-reviewAnalyze model traffic and team budgetsData & AIPrototype library
member-insightsSummarize aggregate, permitted member experience signalsMember ExperiencePrototype library
service-feedbackSynthesize support trends and actionable themesMember ExperiencePrototype library
budget-analysisExplain budget variances from approved finance aggregatesFinancePrototype library
cost-optimizationIdentify infrastructure cost opportunities for reviewFinancePrototype library
job-posting-draftDraft role descriptions from approved people policiesHRPrototype library
onboarding-guideAssemble approved team and policy onboarding referencesHRPrototype library
policy-compareSurface changes for legal and compliance ownersLegalPrototype library
contract-briefPrepare an authorized summary for legal reviewLegalPrototype library

Profile

Illustrative account information for this public prototype.

Demo User
No personal information is stored
Display name
Demo User
User ID
demo.user@example.com

AI Gateway

Illustrative scenario data for simulated model routes, controls, and usage — one console.

Illustrative scenario. Providers, models, traffic, latency, spend, users, teams, budgets, and controls are simulated; they do not describe Costco systems or activity.
Requests
128,400
▲ 11% vs last mo
Tokens
342M
▲ 8% vs last mo
Est. spend
$9,120
76% of budget
Cache-hit
27%
▲ saves ~$2.4k
Error rate
0.6%
▼ 0.2 pts
p50 latency
480 ms
across providers

Illustrative Model Traffic

This month
ModelRouteTokensSpendSharep50 latency
Llama 3.3 70BWorkers AI156M$2,140310 ms
Claudevia AI Gateway98M$3,980720 ms
GPT-4ovia AI Gateway61M$2,510640 ms
Workers AI embeddings (bge)Workers AI27M$49040 ms

Spend vs. Budget

1 day remaining
$9,120spent of $12,000 cap
76%
On track · ~$2,880 left with 1 day
Illustrative Users
Demo User 0142M tok $1,180
Demo User 0231M tok $960
Demo User 0328M tok $840
Demo User 0422M tok $610

Illustrative Usage by Workspace / Team

342M tokens total
Data & AI
121M tokens · $3,240
Central Engineering
89M tokens · $2,460
Member Experience
62M tokens · $1,510
Merchandising & Supply Chain
41M tokens · $1,020
Security & Compliance
29M tokens · $890
Model observability & controls powered by Cloudflare AI Gateway

Governance

Illustrative guardrail settings modeled with Gatekeepers + AI Gateway, resource-scoped access, audit trails, and human approval.

Illustrative settings. Every model, limit, retention period, approval, and control below is simulated; no Costco policy or configuration is connected.

Per-team allowed models

Restrict which providers each workspace can call.

Llama 3.3ClaudeGPT-4o+ embeddings

Monthly spend caps

Hard limits per team; agents stop before overrun.

Data & AI $4,000Central Engineering $3,000Merchandising & Supply Chain $2,000Security & Compliance $2,000

PII redaction

Strip sensitive fields from prompts before they leave.

Enabled

Prompt / response logging

Full request logs retained for audit & review.

Enabled · 90-day retention

Rate limits

Per-team request ceilings to protect budgets.

600 req / min|burst 1,000

Raise Merchandising & Supply Chain cap to $3,000

Simulated change queued by an agent — needs a human sign-off.

Requires approval

AI Gateway Explorer

Explore simulated aggregate model traffic for This month.

4 models
ModelRouteTokensSpendSharep50
Llama 3.3 70BWorkers AI156M$2,14042%310 ms
ClaudeAI Gateway98M$3,98024%720 ms
GPT-4oAI Gateway61M$2,51018%640 ms
Workers AI embeddings (bge)Workers AI27M$49016%40 ms

Review spend cap change

Merchandising & Supply Chain · Monthly spend cap

Current cap$2,000
Requested cap$3,000

Simulated change queued by an agent — needs a human sign-off. Approval updates this demo for the current session only.