The corpus answers. The search team disappears.
The discovery primitive of the estate: everything the data plane holds, findable by meaning — behind a front door that serves today, with every gate to the rest stated in the open.
Accumulating records is free — every business does it by existing. Making them answer a question is still a profession. The default offer to a builder holding a corpus is the machinery around findability: a cluster to size, shards to place, analyzers to configure, synonyms to curate, relevance to hand-tune, and a reindex pipeline that breaks the day the schema changes. The managed wave called that bluff halfway — a real class of search services now sells an index with no cluster to size — and kept the silo: an external index that knows nothing about the types of the records it holds, fed by sync jobs the builder writes, owns, and debugs. The corpus took no effort to accumulate; asking it a question in words the records never used is apparently still a department.
The tax lands hardest exactly where the estate's whole premise lives: on builders and businesses too small to carry a search practice — and on agents, for whom retrieval is not a feature but the first act of nearly every request: find, then reason. A corpus that cannot answer by meaning is dark to the machine economy. If findability is sold at the unit of the cluster, the smallest businesses and every agent stay locked out of their own records.
Three things in this estate are the substrate itself: the studio, the platform, and the runtime. This is deliberately not a fourth. searches.do is the discovery primitive the platform operates — the index over the data plane, wearing its own door because the builder who arrives holding a corpus that must answer "which one" is a different ICP from the builder holding state that must persist, and a brand here is one ICP and one motion.
It rounds out the data plane's sub-batch: database.do persists the record, the state and object doors hold the live and the large, and this door is what makes any of it findable — the layer the rest of the plane is mute without. Persistence answers keep this; search answers which one. In the estate's own registry the coordinate is exact: noun Search, verb search, type primitive, subcategory discovery — filed at priority P1, status planned, a filing this record reports at face value on the bindings slide rather than editing the books from a deck.
// the intended contract — stated as design, not as a live warranty
const idx = await search('catalog') // an index, held by name
await idx.upsert({ id, title, body, price }) // typed by the data plane's shared semantic types
await idx.query('affordable crm for a two-person firm') // answered by meaning, ranked, typo-tolerant
There is nothing else to author. The design — stated here as intent with its public gate below, not as a live self-serve promise: the declared index is the whole artifact, built over the same shared semantic types the data plane already holds, so there is no sync job to write and no external silo to feed; the substrate carries what a search practice used to — shards, analyzers, relevance tuning, reindexing. The live front door itself positions the full reach — vector similarity, full-text matching, hybrid ranking, typo correction, filters and facets — and this record treats that as the door's stated ambition, posting each piece as capability only when the self-serve loop below can demonstrate it.
The public self-serve loop — sign up, declare an index, get your first ranked answer — is not yet the thing this record can post. The live page headlines latency, corpus-size, and edge-location figures; this record does not adopt them, or any performance or relevance figure, until benchmarks publish with their method and window. Capability claims post behind this gate.
Concreteness over adjectives: each door below was checked cold on 2026-07-30 and re-verified 2026-07-31, and carries its own state and its own evidence URL — never one URL evidencing several domains. Serving is a liveness fact, not a tenancy claim: nothing here asserts external tenancy, metered billing in production, or a usage roll. Those publish behind their own gates.
searches.do serves. The front door a builder would resolve is live
under its own identity and sells this layer in its own words — semantic
search engines: vector, full-text, and hybrid ranking with typo
tolerance, filters, and facets.
The gateway routes this primitive as a named service today: GET https://apis.do/searches returns a machine-readable JSON record — no
login, no signup — naming the service, its domain searches.do, its
description "Search Engine", its category data, and its status
available.
The estate's discovery surface is not a diagram — it answers queries
cold: GET https://apis.do/search?q=searches returns ranked,
machine-readable results to a caller with no login, and the result for
that query is this service's own record. The mechanism this door sells
is the mechanism through which a machine finds this door.
docs.platform.do serves — the platform's shared docs surface, which is
where the front door's docs links resolve today. The domain's own docs
path is a separate amber on the bindings slide.
platform.do serves — the operator's front door.
database.do serves — the sibling data-plane primitive: the records
this layer exists to make findable.
functions.do serves — the execution sibling: the compute that issues
queries.
agents.do serves — the runtime whose agents are the machine queriers
this primitive is built to answer.
The ambers, worn in the open — each the exact distance between what serves and what this door intends to be. One of them runs the unusual direction: the estate's own books lag its live door.
The gateway's service record points a machine at searches.do/api as
this service's own API address — and that address answers today with an
HTML page carrying the sibling gateway's identity ("APIs.do — Connect
Any API"), not this primitive's machine record. A machine that follows
the estate's own pointer finds a human page wearing another door's name.
The claim flips when the address serves this service's machine record;
queued in the decision queue as a root-surface item, non-blocking,
because no green claim above asserts anything about that address.
searches.do/docs answers 404 and searches.do/llms.txt answers 500
today; the front door's docs links resolve to the platform's shared docs
surface instead, which serves and is posted above. The claim flips when
the domain's own docs path and machine index answer at its own apex.
The domain registry still files searches.do at status planned, priority P1 — filed before the door lit, and not yet updated to match the live surface. The record reports the books at face value in both directions: the door is posted above with its evidence, and the filing is reported here as it stands until the registry flips.
Primary motion is B2D: the buyer is a developer who evaluates in the docs and converts at the first relevant result — no sales motion, no demo call, no procurement. The evaluation surface is the product surface, which is why the self-serve gate on the contract slide is the deck's most important amber. Secondary is B2A — and this door holds the estate's shortest path to it, because the first step of the machine motion already serves: the gateway answers a cold discovery query with ranked machine-readable results, no login, and this service's own record is among them. Retrieval is the first act of nearly every agent request; the door that sells retrieval is also the mechanism by which machine buyers find every other door. Purchase and settlement for the machine motion gate on the contract surface, exactly as the sibling records state for theirs.
Layer-1 economics at the retrieval grain: fixed cost is the shared substrate — shards, analyzers, relevance machinery, the operations practice run once for everyone; each additional index is a namespace on it, so blended margin improves with density while the metered model follows the documents indexed and the queries served.
Retrieval is a primitive whose marginal cost is honest by nature: documents indexed and queries served are the work, which is exactly why the metered model fits it — the substrate's search practice is a fixed cost amortized across every tenant, and the variable cost tracks the corpus and its questions. What the builder stops paying for is the part that never belonged to their corpus: the standing cluster and the profession of tending it. And there is no regulatory floor anywhere in this function: nothing in answering a query reserves a step for a statutory person, so the implementation mix migrates all the way to Code.
Metered on retrieval — documents indexed and queries served — is the intended model, and the rate card IS the pricing surface: it binds when it posts at the contract surface — verbs, protocol, rate card, guarantees — not before, and never as prose in a deck. No figure is published or implied until then.
Index counts, query volumes, and the internal-versus-external split are gated. Each figure publishes with its window and base or it does not publish.
every brand the estate launches needs its corpus findable on the estate stack this primitive anchors — demand generated by the portfolio’s own search process, structural before commercial; the usage roll publishes behind its stack#1 §A5 gate or not at all
the estate’s gateway routes /searches as a named service AND answers discovery queries cold at its own /search endpoint — when the buyer is an agent, retrieval IS the distribution channel, and this is the door that sells retrieval
built over the data plane’s shared semantic types, one estate over from the store that holds them — no sync jobs to write, no external silo to feed; the tenancy this layer earns is the integration it deletes, and it holds only as long as the contract stays worth staying for
functions, data, and discovery are composed runtimes under one operator and, when it posts, one contract — unbundling the primitive re-creates the sync-and-silo burden the builder came here to delete
Serving is a liveness fact, not a tenancy claim: each posted URL below evidences that one door resolves — not that anyone occupies it.
searches.do serves — the primitive's front door is live under its own
identity.
apis.do/searches serves machine-readable JSON — the gateway's service
record for this primitive resolves for a machine with no login, status
available.
The gateway's own discovery endpoint answers a cold query with ranked machine-readable results — and finds this service.
The domain's own machine door — today an HTML page wearing the sibling gateway's identity, at the very address the gateway's record points to — is the next gate, and the most important one for the B2A leg: a discovery primitive a machine cannot resolve at its own address is a promise, and this deck declines to make it in present tense.
The domain's own docs and machine index lag its live apex; the shared platform docs surface serves in the meantime and is posted above with its own evidence.
The domain registry's own filing — planned, P1 — lags the live door; the record wears the lag rather than editing the books from a deck.
The public self-serve loop and every performance and relevance figure gate together — benchmarks publish with their method and window, or not at all.
No figure is published or implied until the card posts where it binds.
Usage figures — index counts, query volumes, and the internal-versus-external split — remain gated: each publishes with its window and base, or it does not publish.
The front door is searches.do — it serves today.
If this was forwarded to you: searches.do is the discovery primitive of the startups.studio estate's infrastructure layer — the index over the data plane, rounding out the sub-batch in which database.do persists the record and this door makes it findable: persistence answers "keep this," search answers "which one." It is deliberately not one of the estate's three substrate properties, and its deck says so; it is the primitive under them, sold to the builder who has a corpus and refuses to hire a search practice to make it answer. What is live is posted with a URL checked cold — including the estate's own gateway finding this very service through the mechanism this door sells; what is not is pending with the gate that flips it — the ambers it wears openly: the machine door at its own address, the domain's own docs and machine index, the registry filing that lags the live door, the self-serve path with its benchmarks, the rate card, and the usage figures — index counts, query volumes, the internal-versus-external split — behind their stack#1 §A5 gate. Judge it by what is posted, and by how plainly it labels what is not.