HomeBusiness lines
Business Lines

Four business lines covering identity, agents, private domain and learning

Every business line has its own kernel and runtime, yet they share one set of engineering principles. Open any line to see its capability matrix and architecture layers.

Every business line has 11 subpages
01
OverviewPositioning, core capabilities and code scale
02
Scenarios & FAQWhere it lands, and the questions we get
03
FeaturesFine-grained capabilities by business domain
04
ModulesHow the codebase splits into modules, and what each owns
05
API contractPublic endpoints and methods
06
ArchitectureLayering and key data flows
07
Scale & benchmarksVerifiable benchmarks and code facts
08
SecurityTrust boundaries and compliance footing
09
Deploy & integrateDelivery forms and how to plug in
10
ComparisonHow it differs from the alternatives
11
RoadmapShipped and in progress
UIAMGA
Universal Identity & Access Management
Unified identity & access management

A unified identity control plane for people, service accounts and AI agents. Built on Kotlin, Spring Boot 4 and Spring Security 7 with an embedded OAuth2 authorization server: 16 data domains, 56 tables and 77 controllers covering everything from tenant isolation to tool-level authorization for agents, homogeneous across MySQL and PostgreSQL.

Consolidate the accounts, permissions and audit trails scattered across every business system into one governable identity kernel.

Kotlin 2.2Spring Boot 4Spring Security 7OAuth 2.1 / OIDCjOOQLiquibase
Highlights
  • Embedded OAuth 2.1 / OIDC authorization server: authorization code, client credentials, refresh tokens and token exchange
  • Strong multi-tenant and multi-space isolation, with tenant_id in the JWT as the single source of truth
  • Fine-grained RBAC: functional and data permissions on two tracks, taking effect immediately
  • WebAuthn / passkeys, magic links, TOTP MFA, device management, IP rules and sensitive-word policies
  • Four Agent IAM pillars: machine principals → delegation chains → multi-hop propagation → MCP tool authorization
  • Connector ecosystem: WeCom, WeChat Open Platform, mini programs, GitHub and Google out of the box
4
identity principal types modelled uniformly
2×
MySQL / PostgreSQL homogeneous
<50ms
token validation P99
100%
permission changes effective in real time
Code Facts
16data migration domains
56core business tables
77HTTP controllers
82versioned migration files
UniclawBeta
Multi-tenant AI Agent Platform
Enterprise multi-tenant AI agent platform

Digital workers that think, remember and grow. Built on NestJS 11 and Prisma 7: 25 business modules covering the cognition loop, three-tier memory, a five-layer persona, skill evolution and multi-agent collaboration; 19 built-in tools ready to use; multi-channel access via WeCom, Feishu, DingTalk, web chat and API.

Not another chatbot shell — an agent runtime with a cognition loop and long-term memory.

NestJS 11TypeScriptPrisma 7LangChainLangGraphMilvus
Highlights
  • Four cognition engines: intent-extractor → plan-engine → assess-engine → reflect-engine
  • Three-tier memory: session → episodic → semantic, with decay and context-overflow governance
  • Five-layer persona: role, tone, boundaries, domain knowledge and behavioural policy injected in layers
  • 19 built-in tools: web search, SQL queries, chart generation, code execution, email, knowledge retrieval and more
  • Multi-agent collaboration: orchestrator, supervisor and a communication protocol
  • Multi-channel access: WeCom (SCRM pull), Feishu (push API), DingTalk (push API), web chat (WebSocket)
7×24
unattended service window
3 tiers
memory tiers
5 layers
persona layers
N+
multi-agent orchestration
Code Facts
25business modules
19built-in tools
41data models
4cognition engines
UniscrmGA
Private Domain SCRM
WeCom private-domain SCRM

Turn WeChat and WeCom user assets into a private-domain growth engine you can operate, measure and replicate. Built on Java / Kotlin and Spring: 16 WeCom business modules and 132 controllers covering customer assets, conversation archiving, group operations, QR-code acquisition, content marketing, customer service and risk control.

From the first friend request to repeat purchase — the whole journey is traceable, measurable and reviewable.

JavaKotlinSpring BootWeCom APIMySQLRedis
Highlights
  • Conversation archiving: compliant retention of chat history, searchable and auditable, with employee consent and watch-list mechanisms
  • Customer assetisation: profiles, tagging, custom fields, merge-and-dedupe, and handover on employee departure
  • Group operations: group SOPs, welcome messages, group tags, transfers and automated tasks
  • Multi-channel acquisition: staff QR codes, customer QR codes, group QR codes, campaign codes and a lead pool
  • Content marketing: articles, forms, mini-sites, posters, short links and share tracking
  • Risk control: sensitive words, content audit, unfriend alerts and churn warnings
100%
compliant conversation archiving
SOP
group operations automation
end-to-end
source attribution tracking
real-time
conversion dashboards
Code Facts
132HTTP controllers
16WeCom business modules
6conversation archive object types
12QR-code and acquisition capabilities
UnilearningGA
Modular Online Learning Platform
Unified online learning platform

An online learning SaaS for enterprises, institutions and individuals, rebuilt as a Go modular monolith: 8 business domains (auth / cms / eas / ocs / oms / osm / quiz / ai) aggregated in-process, folding 6 microservices into 1 binary and 1 container, with domains communicating only through api contracts and the internal wall enforced by the compiler.

From course publishing to AI-assisted grading, every step of the teaching loop is a business domain that can evolve independently.

Go 1.27gingormPostgreSQLMySQLJWT
Highlights
  • Course tree and learning records: a materialised path tree where progress bubbles up the ancestor chain automatically
  • Four courseware types — content, page, video, media — with unified progress tracking and resume
  • Question bank and exams: single choice, multiple choice and true/false papers, scored and explained on submission
  • AI first-pass grading: the LLM drafts, the teacher has the final say — AI never decides for the teacher
  • Online store: courses as purchasable goods, with the order as proof of purchase
  • Academic scheduling: classes, members and timetables, with three front-end routes compatible with the legacy system
8
business domain modules
6→1
microservices folded into one monolith
2
database dialects
0
direct cross-domain dependencies
Code Facts
8business domains
3front-end aggregation routes (uv1/tv1/admv1)
4courseware forms
17end-to-end smoke tests
Also

Other directions

Historical experience and new exploration — both judged by what we can actually deliver.

Blockchain +Blockchain industry solutions

Deep blockchain experience across industries, from advisory through to delivered systems.

Private-domain growth advisorAdvisory & coaching

Process, product, engineering and management working together as end-to-end advisors for private-domain operations.

Get in touch

Hand the complexity of identity, agents and private domain to one governable kernel

Whether you are replacing an existing IAM, building an agent platform, or trying to make private-domain operations actually work — start with a 30-minute architecture call. We will first judge whether this is the kind of problem we are good at, and say so plainly if it is not.