Platform services
Five services form the durable substrate beneath every Campus application. They compose, but none silently grants authority belonging to another.
| Service | Configure | Provides |
|---|---|---|
| CampusOS | identity and policy | Accounts, permissions, data, events, applications, tools, placement, and topology. |
| Campus Compute | hardware and lifecycle | Isolated execution, durable volumes, private networking, and public reachability. |
| Campus Intelligence | model and budget | Provider-compatible inference without handing reusable credentials to apps. |
| Campus Payments | intent and policy | Value movement, authorization, receipts, products, and paid service admission. |
| Campus Distribution | package and audience | Build, publish, install, promote, roll back, and update applications. |
Independent boundaries
Compute does not imply network publication. A permission does not bypass a budget. Installing an app does not make it trusted. A public route does not carry the owner’s identity. A payment proof does not grant an unrelated tool.
The installation principal and its exact grants tie these services together without collapsing their boundaries.