HALO workflow-first sourcing decision
Status: converged research decision · 2026-08-29 Scope: multi-persona product architecture, full-SaaS candidates, niche live products, and verified GitHub donors. Client anchor: block/buzz ↗ is selected for the collaboration layer. Boundary: research only. repo/ was not modified and no Convex mutation was run.
The corrected answer
HALO is not “a CRM with some missing pages.” It is a multi-persona agency operating system:
- owners/admins need exceptions, money, decisions, risk, access, and a morning command
centre;
- managers need creator lifecycle, campaigns, shifts, QA, approvals, and handoffs;
- chatters need a fast Discord-like execution workspace with creator-scoped context;
- creators/models need a deliberately restricted portal for onboarding, briefs,
documents, status, statements, and support;
- referral partners and staff need their own narrow records, work, and money views;
- agents need first-class identities, bounded tools, evidence, and human approval.
The earlier hunt underperformed because it searched for replacements for existing screen labels. The new campaign searched the jobs around those screens, whole operating systems, niche creator-agency products, and adjacent production/knowledge/workflow categories.
The recommendation is not one giant replacement and not a loose bag of repositories. It is a coherent composition:
HALO identity + domain core
creators · staff · permissions · contracts · Drive/content · referrals · money
|
| server-side adapter, stable IDs, typed links, outbox/inbox events
v
Buzz collaboration + agent plane
channels · threads · DMs · canvases · huddles · media comments · workflows · agents
|
+-- bounded specialist rails only where a real workflow proves the need
Buzz is genuinely integrated, but it does not become the CRM or money ledger. That source-of-truth split is the difference between a modular product and six conflicting SaaS products sharing the same customer data.
Operator/community evidence sharpened four non-negotiable product rules: chat is promoted into a structured request/decision/action instead of becoming the record by default; approvals bind a named person to an exact asset version; content and payment have separate state machines; and chatters receive narrow shift/creator context while creators receive a bounded external portal rather than access to staff operations.
What the campaign actually covered
- Local Foundry identity spine: 1,358,200 RepoCards searched as a candidate source.
- Curated repository corpus: 307,180 repositories plus human-curated co-placement.
- GitHub wide funnel: 77 explicit query families, 263 captured raw rows in the fully
visible runs, 18 repositories in 17 promoted rows, and 8 recorded rejects. Every cited repository was refreshed through gh api repos/OWNER/NAME; every NOASSERTION finalist had its license source inspected.
- Live products: 11 system-class families plus 15 bounded products were evaluated
against the eight operator journeys using first-party product/documentation evidence.
- Fixed integration source: Buzz's architecture, event/API surface, identity model,
channels, workflows, agent model, search, audit, and implementation gaps were inspected from a read-only upstream source reference.
GitHub's authenticated search quota reached zero after the wide funnel. Direct repository verification remained available and was completed for everything promoted. This limits further breadth in this snapshot; it does not turn an unverified search hit into a recommendation.
The full-system shortlist
| Rank | Product | Real HALO job | Decision beside Buzz | Why it survives |
|---|---|---|---|---|
| 1 | Twenty ↗ | Salesforce-like relationship objects, timelines, workflows, roles, APIs and AI-oriented CRM | Study and run one bounded creator-relationship pilot | Strongest practical open AI/Salesforce-shaped system and closest TypeScript/React fit. It must not silently become a second creator authority; source is mostly AGPL with exceptions and enterprise-marked files. |
| 2 | ERPNext ↗ / Frappe | Accounting, invoicing, expenses, HR, attendance, payroll, CRM and projects | Back-office reference; isolated pilot only | Deepest coherent OSS back office. It earns financial authority only after synthetic/read-only reconciliation; its Python/Frappe datastore and ERP semantics are not HALO's creator-facing shell. |
| 3 | Salesforce + Agentforce ↗ | Enterprise benchmark for one metadata/permission/automation/agent platform | Reference or narrow paid proof | Strongest match if Camron's remembered “AI Salesforce” was an enterprise AI action platform. Too costly and heavy for a near-term re-platform. |
| 4 | Attio ↗ | Modern linked relationship OS with email/calendar, notes, tasks, workflows and AI/MCP | Commercial relationship pilot or pattern donor | Strongest lighter commercial alternate to Agentforce; proprietary and still another record authority. |
| 5 | Influs ↗ | Niche talent-agency daily work, campaigns, deliverables, approvals, creator portal and payment status | Workflow benchmark and one-campaign pilot | Closest public niche match to “what needs me today?” and roster-to-deliverable-to-payment operations. Public evidence does not yet show a robust API or money ledger. |
| 6 | Influno ↗ | Niche creator/studio deals, contracts, invoices, payout splits, statements and reconciliation | Request a controlled trial; study money/trust model | Best vertical benchmark for the connected creator-money lifecycle, but the public evidence is marketing-led and must be proven with export, reversals and reconciliation. |
| 7 | AFFiNE ↗ | Meeting notes, briefs, SOPs, linked creator context, decisions and handoffs | Sanitized knowledge pilot / pattern donor | This is the important category the first hunt missed. It is not the CRM or ledger, and its backend has a mixed/commercial license boundary. |
| 8 | SuiteDash ↗ | White-label client/creator portal, CRM, projects, e-sign, billing, messaging and LMS | Portal benchmark or bounded commercial pilot | Useful proof of a coherent external persona shell; do not duplicate HALO's creator identity and money truth without a deliberate re-platform decision. |
NocoBase, Directus, Airtable Omni, Odoo, Corteza, erxes, Rocket.Chat, Mattermost and Zulip remain valuable comparison systems. None has a cleaner role beside Buzz than the ranked set. In particular, Zulip/Mattermost/Rocket.Chat/Discord no longer compete to be the primary chatter product: Camron selected Buzz.
The niche repository shortlist
These are not “more apps to install.” Each survives because it fills a specific workflow that the whole-system candidates do not solve cleanly.
| Capability | Candidate | Decision | Exact boundary |
|---|---|---|---|
| Meeting capture | Vexa ↗ | Integrate/probe | Capture Google Meet/Teams/Zoom transcripts and speaker evidence after consent; a human-approved summary becomes a HALO decision/action. Buzz receives the discussion link, not an unrestricted transcript dump. |
| Automation | Activepieces ↗ | Integrate/probe | Use for retryable onboarding, Drive, notification and approval plumbing. HALO validates and records all consequential commands. Core/enterprise license boundary must be respected. |
| Content production | Kitsu ↗ + Zou ↗ | Study or API-level sidecar | Best adjacent production model for briefs, versions, status, deliveries and approvals. Keep HALO's Drive provenance and creator model authoritative. |
| Search/RAG | Qdrant ↗ plus QMD ↗ patterns | Integrate only after ACL probe | Index redacted, authorized chunks with immutable source IDs and return citations. Retrieval never becomes authorization. |
| Publishing | Mixpost ↗ | Bounded sidecar if required | Own provider tokens, schedules and retries only; HALO owns brief, approval, asset, creator and provenance. Verify provider freshness first. |
| Agency money/time pattern | Miru ↗ | Study | Useful small-agency reference for time, invoices, expenses, payments and benefits; not a creator-liability ledger. |
| Modern CRM UI | Atomic CRM ↗ and NextCRM ↗ | Pattern donors | React/shadcn-shaped donors for relationship, project, invoice and document UX; neither is the full operating system. |
Buy the commodity trust boundaries
Some important capabilities should not be reconstructed from a repository:
- 1Password Business: move creator/platform secrets out of Convex and the client
bundle; HALO stores references and ownership, not passwords.
- Stripe Connect / Trolley / Deel: payment, payout, tax-form and contractor rails where
the legal model fits. HALO still owns the double-entry liability ledger, approval, statement, dispute and reconciliation history.
- Frame.io or Filestage: professional media/document review if one real content slice
proves HALO should buy rather than build versioned approval.
- MaestroQA: chatter QA/calibration only if a real quality program outgrows HALO's
scorecard needs.
Buzz integration decision
The source-level conclusion is sidecar, not code merge:
- one HALO agency community first;
- staff/chatters and read-only agents first; creator guest rooms later;
- HALO server authority provisions Buzz memberships and resource rooms;
- stable opaque HALO IDs and allowlisted deep links connect creator, shift, campaign,
content-review and exception context;
- an idempotent outbox/inbox adapter exchanges non-financial events;
- Buzz actions create proposals/tasks; HALO re-authorizes and requires a human for money,
contracts, permissions, credentials, Drive or creator-state mutations;
- HALO remains usable during a Buzz outage.
Verified gaps prevent unrestricted production autonomy today: no production rate limiter was found in the inspected implementation; workflow approval runs do not persist/resume; send_dm and set_channel_topic are stubbed; NIP-FI is draft/optional rather than a finished SSO bridge; roles are too coarse for HALO domain authorization; and huddle recording is not built. The full evidence and rollout are in research/sourcing-campaign/buzz-integration.md.
What to test—not merely discuss
- Trust containment: fix server identity/authorization and remove plaintext secrets
before any sidecar receives live data.
- Buzz synthetic deployment: exercise upgrade, backup/restore, key recovery,
offboarding, search isolation, ingress rate control, retention, webhook replay and a full Buzz outage.
- One chatter/manager workflow: provision a creator or shift room, run a handoff,
attach a HALO resource link, use a read-only briefing agent, and measure whether the history is actually easier to retrieve.
- One relationship workflow: model Creator, Brand, Campaign, Staff and Referral
Partner in Twenty using fake data; test permissions, export, deletion, API behavior and whether dual entry appears.
- One vertical workflow: compare Influs against a single campaign from roster through
deliverable, approval, portal and payment status. It must beat a focused HALO slice, not win a feature checklist.
- One memory/content workflow: Vexa or another consented meeting capture writes an
approved action; AFFiNE is tested with sanitized SOPs/briefs; Kitsu/Zou or Frame.io is tested on one immutable asset-version approval.
- Money last: prove a double-entry creator/referral liability model, payout reversal,
statement and reconciliation before giving ERPNext or any payment rail authority.
Final product position
The strongest HALO direction is:
A creator-agency operating core with Buzz as its human-and-agent collaboration plane, Salesforce-quality relationship and permission patterns, niche creator-agency workflow ergonomics, and bought commodity trust rails.
That preserves the bespoke work Camron has already built while sourcing the areas where the wider software ecosystem is materially better. It also leaves room for different experiences by persona without pretending every user should live in the same dashboard or every module should share the same datastore.