惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google Online Security Blog
Google Online Security Blog
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
D
DataBreaches.Net
V
Visual Studio Blog
M
MIT News - Artificial intelligence
C
Check Point Blog
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
F
Full Disclosure
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
InfoQ
aimingoo的专栏
aimingoo的专栏
L
LangChain Blog
Recorded Future
Recorded Future
B
Blog RSS Feed
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
博客园 - 司徒正美
Forbes - Security
Forbes - Security
美团技术团队
Google DeepMind News
Google DeepMind News
H
Help Net Security
L
LINUX DO - 最新话题
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
Security Affairs
W
WeLiveSecurity
MyScale Blog
MyScale Blog
O
OpenAI News
P
Privacy & Cybersecurity Law Blog
Attack and Defense Labs
Attack and Defense Labs
N
Netflix TechBlog - Medium
T
Troy Hunt's Blog
月光博客
月光博客
Recent Commits to openclaw:main
Recent Commits to openclaw:main
B
Blog
V
V2EX
WordPress大学
WordPress大学
H
Heimdal Security Blog
U
Unit 42
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Simon Willison's Weblog
Simon Willison's Weblog
S
SegmentFault 最新的问题
SecWiki News
SecWiki News
D
Docker
Blog — PlanetScale
Blog — PlanetScale
S
Secure Thoughts

Show HN

GitHub - villagesql/villagesql-skills: Agent skills for VillageSQL - gemini-cli-extension; claude-code-plugin GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - aeriesec/orgforge: Synthetic corporate dataset generator for AI agent evaluation.
jflynt76 · 2026-06-12 · via Show HN

License: MIT DOI Python 3.11+ Run Tests Dataset on HuggingFace

A deterministic corporate simulator for generating ground-truth ecosystems and evaluating enterprise AI agents

OrgForge corpus overview

OrgForge simulates weeks of realistic enterprise activity — Confluence pages, JIRA tickets, Slack threads, Git PRs, Zoom transcripts, Zendesk tickets, Salesforce records, emails, and server telemetry — grounded in an event-driven state machine so LLMs can't hallucinate facts out of sequence.

The dataset is the exhaust of a living simulation. Engineers leave mid-sprint, forcing deterministic incident handoffs, ticket reassignments, and CRM ownership lapses. Knowledge gaps surface when under-documented systems break. New hires build their internal network through simulated collaboration. Stress propagates through a live, weighted social graph. Every artifact reflects the exact state of the org at the moment it was written.


Table of Contents

  • Why Does This Exist?
  • What the Output Looks Like
  • What Gets Generated
  • Architecture & Mechanics
  • The Departure Cascade
  • Insider Threat Simulation
  • Quickstart
    • Setup Options
    • Option 1 — Everything in Docker
    • Option 2 — Local Ollama, Docker for MongoDB Only
    • Option 3 — Cloud Preset
    • Running on AWS EC2
  • Configuration
    • Quality Presets
    • Key Config Fields
    • Dynamic Org Lifecycle
  • How the Event Bus Works
  • Memory Requirements
  • Project Structure
  • Roadmap
  • Adding a New Artifact Type
  • Contributing
  • Citation
  • License

Why Does This Exist?

When building AI agents that reason over institutional knowledge, you need a realistic corpus to test against. The only widely-used corporate dataset is the Enron email corpus — 25 years old, legally sensitive, and covering one company in crisis.

OrgForge generates that corpus from scratch, parameterized to any company, industry, or org structure. LLMs write the prose, but the facts — who was on-call, which ticket was open, when the incident resolved, who just left the team, and which customer SLA was breached — are strictly controlled by the state machine.

The central design bet: grounding LLM output in a deterministic event log makes the dataset actually useful for evaluating retrieval systems. You have ground truth about what happened, when, who was involved, and what the org's state was — so you can measure whether an agent surfaces the right context, not just plausible-sounding context.


What the Output Looks Like

Here's what a slice of a real simulation produces. An incident fires on Day 8:

slack/channels/engineering-incidents.json — the alert arrives first, timestamped to the millisecond the on-call pager fired:

{
  "ts": "2026-03-10T14:23:07",
  "user": "pagerduty-bot",
  "text": "🔴 P1 ALERT: TitanDB latency spike — connection pool exhaustion under load. On-call: Jax."
}

jira/IT-108.json — opened seconds later, facts pulled from the same SimEvent:

{
  "id": "IT-108",
  "type": "incident",
  "priority": "P1",
  "title": "TitanDB: latency spike",
  "root_cause": "connection pool exhaustion under load",
  "assignee": "Jax",
  "reporter": "system",
  "opened": "2026-03-10T14:23:19"
}

confluence/postmortems/IT-108.md — written the next day, linking the same root cause and PR:

This incident was triggered by connection pool exhaustion under sustained load, first surfaced in IT-108. The fix landed in PR #47 (merged by Sarah). A prior knowledge gap in TitanDB connection management — stemming from Jordan's departure on Day 12 — contributed to the delayed diagnosis.

Meanwhile, the datadog/metrics.jsonl time-series data reflects the exact latency spike, Zendesk support tickets from affected customers are automatically escalated to 'Urgent', Salesforce opportunities are flagged as 'at-risk', and end-of-month customer invoices (invoices/) automatically apply SLA credits based on the incident's duration.

None of this is coincidence — it all traces back to one SimEvent that every downstream artifact reads from.


What Gets Generated

A default 22-day simulation produces:

Artifact Description
confluence/ Seed documents, ad-hoc wikis, and post-incident write-ups grounded in actual root causes
jira/ Sprint tickets, P1 incident tickets with linked PRs
slack/channels/ Standup transcripts, incident alerts, engineering chatter, bot messages
git/prs/ Pull requests with reviewers, merge status, linked tickets
zoom/ Verbatim meeting transcripts from sync design discussions, capturing undocumented verbal decisions
salesforce/ CRM accounts and active sales opportunities, including risk flags propagated from active incidents
zendesk/ Customer support tickets and comments, automatically escalated during system outages
emails/ External inbound/outbound emails — customer complaints, vendor messages, HR communications, sales updates
datadog/ Time-series system metrics (metrics.jsonl) and alert payloads (alerts.jsonl) reflecting incident degradation & recovery
nps/ Post-simulation customer satisfaction surveys, scored deterministically based on SLA breaches and support ticket resolution
invoices/ End-of-month customer invoices featuring SLA credit line items calculated directly from incident duration
simulation_snapshot.json Full state: incidents, morale curve, system health, relationship graph, departed employees, new hires, knowledge gap events
simulation.log Complete chronological system and debug logs for the entire run

Architecture & Mechanics

OrgForge is not an LLM wrapper. Four interlocking systems enforce correctness.

👉 Read the full Architecture Deep-Dive here.


The Departure Cascade

The most complex behaviour in the simulation. When an engineer departs mid-sprint, the following fires in order before that day's planning runs:

  1. Incident handoff — active incidents assigned to the departing engineer are rerouted via Dijkstra escalation routing (while the node is still in the graph) to the next available person in the chain.
  2. Ticket & CRM reassignment — orphaned JIRA tickets go to the dept lead. Salesforce accounts and open opportunities owned by the departed employee are flagged for reassignment, maintaining cross-domain ground truth.
  3. Graph recompute — betweenness centrality is recalculated on the smaller graph. Engineers absorbing the departed node's bridging load receive a proportional stress hit.
  4. Knowledge gap propagation — if the departed engineer owned undocumented domains (configured via documented_pct), those gaps are registered in the SimEvent log and surface in subsequent incidents as contributing factors.
  5. employee_departed SimEvent — emitted with edge snapshot, centrality at departure, reassigned tickets, and incident handoffs. Full ground truth for retrieval evaluation.

So when Jordan leaves on Day 12, the postmortem on Day 9's incident doesn't mention her. But the postmortem on Day 15 might: "A prior knowledge gap in auth-service, stemming from a recent departure, contributed to the delayed diagnosis." That sentence is grounded in a real SimEvent, not LLM inference.


Insider Threat Simulation

OrgForge includes an optional insider threat module that layers adversarial behavior on top of the normal simulation — without touching any of the clean simulation paths. When disabled (the default), it is completely inert: no overhead, no additional output, no altered code paths.

When enabled, designated employees exhibit configurable threat behaviors across multiple surfaces: anomalous git activity, off-hours access, sentiment drift in Slack, data staging on their workstation, and IDP authentication anomalies. All threat telemetry is written to a separate security_telemetry/ directory in industry-standard log formats (JSONL, CEF, ECS, LEEF), keeping it cleanly isolated from the normal simulation output so detection agents must work to find it.

The module is designed for building and evaluating insider threat detection systems. Ground truth is always preserved in JSONL regardless of output format.

👉 Read the full Insider Threat reference here.


Quickstart

flow.py is the main simulation entry point. config/config.yaml is the single source of truth for org structure, personas, and quality presets.

Setup Options

Scenario Command Notes
Everything in Docker docker compose up Recommended for first run
Local Ollama + Docker for the rest docker compose up mongodb orgforge Set OLLAMA_BASE_URL in .env
Cloud preset (AWS Bedrock) docker compose up mongodb orgforge Set credentials in .env, skip Ollama

Option 1 — Everything in Docker (Recommended)

git clone https://github.com/aeriesec/orgforge
cd orgforge
docker compose up

First run pulls models automatically (~5–8 min depending on your connection). Subsequent runs start in seconds — models are cached in a named volume.

When the simulation finishes, run the post-processing artifact generators:

python email_gen.py
python post_sim_artifacts.py

Output lands in ./export/.

Option 2 — Local Ollama, Docker for MongoDB Only

Create a .env file:

OLLAMA_BASE_URL=http://host.docker.internal:11434

Then:

docker compose up mongodb orgforge

Linux note: host.docker.internal requires Docker Desktop, or the extra_hosts: host-gateway entry in docker-compose.yaml (already included).

Option 3 — Cloud Preset (AWS Bedrock + OpenAI)

Best output quality. Uses Claude Sonnet for document generation, Llama 3.1 8B on Bedrock for high-volume worker calls, and OpenAI text-embedding-3-large for embeddings.

Set quality_preset: "cloud" in config.yaml, then:

# .env
AWS_ACCESS_KEY_ID=...
AWS_SECRET_ACCESS_KEY=...
AWS_DEFAULT_REGION=us-east-1
OPENAI_API_KEY=...
pip install boto3 langchain-aws openai
docker compose up mongodb orgforge

Running on AWS EC2

Cheap EC2 + Bedrock/OpenAI (no GPU required)

A t3.small works fine — the cloud APIs do all the heavy lifting.

  1. Launch an EC2 instance (Ubuntu or Amazon Linux) and install Docker
  2. git clone https://github.com/aeriesec/orgforge.git && cd orgforge
  3. cp .env.example .env and fill in your credentials
  4. Set quality_preset: "cloud" in config/config.yaml
  5. docker compose up --build -d mongodb orgforge

GPU Instance + 70B Local Models

For Llama 3.3 70B entirely locally, use a g5.2xlarge or g5.12xlarge with the Deep Learning AMI. Uncomment the GPU deploy block under the ollama service in docker-compose.yaml, set quality_preset: "local_gpu", then docker compose up -d.


Configuration

config/config.yaml is the single source of truth. No Python changes are needed for most customizations.

Quality Presets

quality_preset: "local_gpu" # local_gpu | cloud
Preset Planner Worker Embeddings Best For
local_gpu llama3.3:70b-instruct-q4_KM llama3.1:8b-instruct mxbai-embed-large High-fidelity local runs
cloud Claude Sonnet (Bedrock) llama3.1:8b (Bedrock) text-embedding-3-large Best output quality

Key Config Fields

Field Purpose
company_name Injected into all generated prose
simulation_days Length of the simulation (default: 22)
legacy_system The unstable system referenced in incidents, tickets, and docs
crm Enable/disable Salesforce and Zendesk simulation integrations
sprint_ticket_themes Pool of ticket titles drawn during sprint planning
adhoc_confluence_topics Spontaneous wiki pages generated on normal days
knowledge_gaps Static departed employees whose absence creates documentation gaps from day one
org_lifecycle Dynamic departures and hires that occur during the simulation (see below)
roles Maps simulation roles (on-call, incident commander, HR lead) to departments
morale Decay rate, recovery rate, intervention threshold
org_chart + leads Everyone in the company and who runs each department
personas Writing style, stress level, and expertise per named employee
external_contacts Vendors, customers, and cloud providers that get pulled into incidents

Dynamic Org Lifecycle

Engineers can join and leave during the simulation. Departures and hires are scheduled in config and execute before the day's planning runs, so every downstream artifact that day reflects the new roster.

org_lifecycle:
  scheduled_departures:
    - name: "Jordan"
      day: 12
      reason: "voluntary" # voluntary | layoff | performance
      role: "Senior Backend Engineer"
      knowledge_domains:
        - "auth-service"
        - "redis-cache"
      documented_pct: 0.25 # fraction written down — drives gap severity

  scheduled_hires:
    - name: "Taylor"
      day: 15
      dept: "Engineering"
      role: "Backend Engineer"
      expertise: ["Python", "FastAPI"]
      style: "methodical, asks lots of questions before writing code"
      tenure: "new"

  enable_random_attrition: false
  random_attrition_daily_prob: 0.005

On hire, the new engineer enters the graph with cold-start edges below the warmup_threshold, so the day planner naturally proposes warmup_1on1 and onboarding_session events until real collaboration warms the edges.


How the Event Bus Works

Every significant action emits a SimEvent:

SimEvent(
    type="incident_opened",
    day=8,
    date="2026-03-10",
    actors=["Jax", "Sarah"],
    artifact_ids={"jira": "IT-108"},
    facts={
        "title": "TitanDB: latency spike",
        "root_cause": "connection pool exhaustion under load",
        "involves_gap": True
    },
    summary="P1 incident IT-108: connection pool exhaustion",
    tags=["incident", "P1"]
)

Every downstream artifact pulls its facts from the event log rather than asking an LLM to invent them. This prevents temporal drift and hallucination across a multi-week simulation.

The end-of-day day_summary SimEvent captures a structured snapshot of everything that happened:

facts={
    "active_actors":        ["Jax", "Sarah", "Morgan"],
    "dominant_event":       "incident_opened",
    "event_type_counts":    {"incident_opened": 1, "pr_review": 2, "standup": 1},
    "departments_involved": ["Engineering"],
    "open_incidents":       ["IT-108"],
    "stress_snapshot":      {"Jax": 72, "Sarah": 55, "Morgan": 41},
    "health_trend":         "degraded",
    "morale_trend":         "moderate",
}

This is what makes the dataset useful for RAG evaluation: you have ground truth about what happened, when, who was involved, and what the org's state was — so you can measure whether a retrieval system actually surfaces the right context.


Memory Requirements

Preset RAM Required Notes
local_gpu ~48 GB VRAM Llama 3.3 70B — requires A100 or 2× A10G
cloud ~500 MB Only MongoDB + Python run locally

For local_gpu on AWS, a g5.2xlarge (A10G 24GB) runs 70B at q4 quantization. At ~$0.50/hour spot pricing a full 22-day simulation costs roughly $3–5.


Project Structure

orgforge/
├── .github/workflows/    # CI/CD pipelines
├── src/
│   ├── flow.py           # State machine and simulation engine
│   ├── day_planner.py    # LLM-driven per-department daily planning
│   ├── normal_day.py     # Agenda dispatcher — produces typed artifacts per activity
│   ├── crm_system.py     # Salesforce & Zendesk integration and propagation rules
│   ├── planner_models.py # Dataclasses for plans, events, and validation results
│   ├── plan_validator.py # Integrity boundary between LLM proposals and execution
│   ├── org_lifecycle.py  # Dynamic hiring, firing, and knowledge gap propagation
│   ├── graph_dynamics.py # Social graph: stress propagation, edge decay, escalation
│   ├── memory.py         # Vector DB and SimEvent bus
│   ├── email_gen.py      # Reflective post-processing email artifacts
│   └── post_sim_artifacts.py # Deterministic post-processing (NPS, invoices, Datadog)
├── config/               # YAML configurations
├── tests/                # Pytest suite
├── scripts/              # Entrypoint and helper scripts
├── export/               # Output directory for generated dataset
├── README.md
├── ARCHITECTURE.md
└── CONTRIBUTING.md

Roadmap

  • Native integrations for Zoom, Zendesk, and Salesforce CRM
  • Plugin architecture for additional integrations (PagerDuty, Workday, etc.)
  • Domain packs — pre-configured config.yaml templates for healthcare, fintech, legal
  • Export to HuggingFace dataset format
  • Evaluation harness — benchmark RAG retrieval against SimEvent ground truth

Adding a New Artifact Type

  1. Add an event emission in flow.py when the triggering condition occurs
  2. Write a handler that reads from the SimEvent log and generates the artifact

A formal plugin architecture is on the roadmap. Open an issue before starting so we can align on the interface.


Contributing

Contributions are welcome. Please read CONTRIBUTING.md before opening a PR. For new domain configs or artifact types, open an Issue first.


Citation

If you use this work, please cite:

@article{Flynt2026,
  author = {Jeffrey Flynt},
  title  = {OrgForge: A Multi-Agent Simulation Framework for Verifiable Synthetic Corporate Corpora},
  year   = {2026},
  url    = {https://arxiv.org/abs/2603.14997}
}

License

MIT — see LICENSE.